Home / Industry

A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign

ReversingLabs uncovered a device code phishing campaign that abused Microsoft 365’s legitimate OAuth 2.0 Device Authorization Grant flow to access victims’ accounts. Instead of stealing passwords using a counterfeit login page, the attackers persuaded victims to complete a legitimate authentication process that authorized an attacker-controlled device.

The researchers listed hundreds of URLs as network IoCs for the attack. We cleaned up the list of IoCs aided by the WhoisXML API MCP Server by extracting unique ones from the subdomains then weeding out those that were owned by legitimate entities. In the end, we analyzed 290 IoCs in all comprising 51 domains and 239 subdomains.

Our DNS deep dive into the campaign led to these discoveries:

  • Three distinct client IP addresses that communicated with one of the domain IoCs
  • One domain IoC appeared in a typosquatting group with two look-alikes
  • One domain IoC that was likely registered with malicious intent
  • 35 email-connected domains
  • 87 IP addresses, all were confirmed malicious
  • 757 string-connected domains, one was confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

Microsoft 365 Device Code Phishing Subdomain IoC Analysis

We kicked off our analysis by zooming in on the 239 subdomain IoCs under 56 apex domains with the help of our homegrown tools via the WhoisXML API MCP Server. We summed up our findings for the subdomains under five sample apex domains below.

SUBDOMAIN IoC APEX DOMAINWXA MCP SERVER FINDING
darnel[.]nl(40 subdomains)Pure DGA redirector farm made up of 40 random alphanumeric hosts; disposable rotating credential/redirect hosts
taskvault[.]nl(16 subdomains)All-random-host redirector farm comprising 16 hosts
horizoralabs[.]com(13 subdomains)Masked registrant; bulk-registered within seconds of ventoraco/corevantaco/scalevantaco; 13 spoofed company-name hosts possibly meant for vendor/BEC impersonation
trenix[.]nl(13 subdomains)Sibling of darnel[.]nl; mixes random hosts with spoofed European company names normally created for vendor/BEC lures
ventoraco[.]com(12 subdomains)Masked registrant; 12 spoofed company names; same bulk batch as horizoralabs[.]com

Overall, the subdomain IoCs point to a single coordinated phishing operation. Many shared Cloudflare nameserver pairs, common registrars, and bulk registrations that were seconds apart, which could serve as evidence of one actor cycling disposable infrastructure.

The threats fall into four patterns—DGA-style random hosts serving as rotating redirectors, hosts spoofing real company names for vendor/invoice BEC lures, generic lures, and brand impersonation for credential harvesting. In addition, most remain active behind Cloudflare, with one live GCP backend and only one registry-suspended domain so exposure is likely ongoing.

Microsoft 365 Device Code Phishing Domain IoC Investigation

Next, we took a closer look at the 51 domain IoCs.

First, sample network traffic data from the IASC revealed that three unique client IP addresses under a single ASN communicated with the domain IoC firmtix[.]com via six DNS queries on 9—18 June 2026.

Typosquatting API also showed that the domain IoC nextaragroup[.]app appeared in a typosquatting group along with two look-alikes—nexaragroups[.]com and nexaragroups[.]in. They were all created on 23 April 2026.

In addition, we learned that the domain IoC couglesrecycilng[.]mom was likely registered with malicious intent 324 days before it was identified as an IoC on 12 June 2026. It appeared on the First Watch Malicious Domains Data Feed on 23 July 2025.

Next, we queried the domain IoCs on WHOIS API and completed missing data points aided by Domain Info API. We found out that:

  • A huge majority were fairly new, as they were created between 23 July 2025 and 2 June 2026.
  • They were administered by seven registrars.

  • While 35 did not have registrant countries on record, the remaining 16 were registered in just two countries.

To cap off, we queried the domain IoCs on DNS Chronicle API and discovered that 36 recorded 287 historical domain-to-IP resolutions over time. Take a look at more information for five examples below.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
couglesrecycilng[.]mom3808/02/25–06/19/26
trenix[.]nl1505/30/23–05/17/26
sparkaxis[.]org1412/26/25–05/24/26
notivora[.]nl1304/14/26–05/25/26
datavaner[.]us1204/19/26–05/22/26

The small resolution volumes for the domain IoCs are not surprising given that they were all fairly new when they figured in the campaign. Many of them also continue to post resolutions at the time of writing.

New Microsoft 365 Device Code Phishing Artifact Discovery

We then moved onto hunting for new artifacts that could be connected to the threat starting with querying the domain IoCs on WHOIS History API. We learned that 16 had six unique email addresses in their historical WHOIS records.

Upon further scrutiny, we learned that three were public email addresses. We queried them on Reverse WHOIS API and uncovered 35 distinct email-connected domains.

Next, we queried the domain IoCs on DNS Lookup API, which led to the discovery of 87 distinct IP addresses.

Threat Intelligence API queries for the IP addresses revealed that they have all been weaponized for various campaigns.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.<

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

Cybersecurity

Sponsored byVerisign

DNS

Sponsored byDNIB.com

Domain Names

Sponsored byVerisign

New TLDs

Sponsored byRadix

Brand Protection

Sponsored byCSC