logo

Device Code Phishing Keeps Evolving. Here’s What to Watch For

ID: f51b1503-17e4-5061-b89b-46810a04e790

STIX ID: report--f51b1503-17e4-5061-b89b-46810a04e790

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2026-07-31

Date Updated: 2026-08-19

...
...

Huntress observed an active campaign of device-code phishing and Microsoft 365 token replay linked to BL Networks (ASN AS399629), with dozens to hundreds of events and multiple successful sign-ins originating from BL Networks IPs (notably 216.203.20.95, 193.149.176.151, 193.149.176.238, 45.61.136.129). The report explains that attackers abuse legitimate authentication flows and trusted infrastructure to obtain and reuse tokens, details observed event counts and timelines, and advises defenders to monitor device-code activity, investigate clustered logins from suspicious ASNs, revoke tokens/sessions, and prioritize behavioral detection over simple infrastructure reputation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.