logo

Spectra Analyze in Action: Hunting Device Code Phishing Pages

ID: 827f6e2c-183d-5cde-9b4a-650c84e5f1ec

STIX ID: report--827f6e2c-183d-5cde-9b4a-650c84e5f1ec

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2026-07-08

Date Updated: 2026-07-19

Author: RL Research Team

...
...

This report details an active Microsoft 365 device-code phishing campaign that leverages the OAuth 2.0 Device Authorization Grant to trick victims into authorizing attacker-controlled devices, rather than capturing passwords. The write-up includes a YARA rule to detect phishing landing pages, instructions for running cloud retro-hunts and hunting results (765 matched samples, with recent activity), plus guidance for retrieving and analyzing matched HTML landing pages in Spectra Analyze for threat hunting and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.