A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign

A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign
ReversingLabs documented a Microsoft 365 device code phishing campaign that abused the legitimate OAuth 2.0 Device Authorization Grant flow to trick victims into authorizing attacker-controlled devices instead of entering passwords on a fake login page. The investigation uncovered 290 IoCs across domains, subdomains, IPs, and email-connected infrastructure, with evidence pointing to a coordinated operation involving typosquatting, brand impersonation, and disposable redirector hosts. #Microsoft365 #OAuth20DeviceAuthorizationGrant #ReversingLabs

Keypoints

  • The attackers abused Microsoft 365’s legitimate OAuth 2.0 Device Authorization Grant flow to capture account access.
  • The campaign used device code phishing rather than a counterfeit login page to persuade victims to authorize attacker-controlled devices.
  • Researchers analyzed 290 IoCs in total, including 51 domains and 239 subdomains.
  • The subdomain infrastructure showed signs of a single coordinated operation using DGA-style random hosts, spoofed company names, and brand impersonation.
  • Most of the infrastructure remained active behind Cloudflare, with one live GCP backend and only one registry-suspended domain.
  • Network and DNS analysis identified three client IP addresses, 35 email-connected domains, 87 malicious IP addresses, and 757 string-connected domains.
  • Typosquatting and malicious registration patterns were observed for domains such as nextaragroup[.]app and couglesrecycilng[.]mom.

MITRE Techniques

  • [T1583.001 ] Acquire Infrastructure: Domains – The operation relied on newly registered and spoofed domains to support phishing and redirect activity (‘bulk-registered within seconds’, ‘malicious intent’, ‘many shared Cloudflare nameserver pairs’).
  • [T1583.003 ] Acquire Infrastructure: Virtual Private Server – The campaign used hosted backend infrastructure, including a live GCP backend (‘one live GCP backend’).
  • [T1588.001 ] Obtain Capabilities: Malware – The article notes that IPs were weaponized for various campaigns, indicating acquired infrastructure or tooling used operationally (‘they have all been weaponized for various campaigns’).
  • [T1598.003 ] Phishing for Information: Spearphishing Link – Victims were directed to legitimate Microsoft 365 device authorization steps via attacker-controlled links/redirects (‘persuaded victims to complete a legitimate authentication process’).
  • [T1566.002 ] Phishing: Spearphishing Link – The campaign used phishing URLs and redirector hosts to lure victims into granting access (‘device code phishing campaign’, ‘rotating redirector hosts’).
  • [T1110.003 ] Brute Force: Password Spraying – Not explicitly described as password spraying; omitted if not directly present.

Indicators of Compromise

  • [Domain ] malicious/phishing infrastructure and redirectors – firmtix[.]com, nextaragroup[.]app, and other 49 domains
  • [Subdomain ] coordinated redirector and lure hosts – darnel[.]nl, taskvault[.]nl, trenix[.]nl, and 236 more subdomains
  • [IP Address ] malicious network infrastructure used across campaigns – 87 distinct IP addresses, plus three client IP addresses
  • [Email Address ] historical WHOIS data used to find related infrastructure – 6 unique email addresses, including 3 public email addresses
  • [Domain-to-IP Resolution ] historical resolution data for domain tracking – couglesrecycilng[.]mom, trenix[.]nl, and 34 other domains with 287 total resolutions
  • [Typosquatted Domains ] look-alike phishing cluster – nexaragroups[.]com, nexaragroups[.]in, and nextaragroup[.]app


Read more: https://circleid.com/posts/a-dns-infrastructure-analysis-of-a-microsoft-365-device-code-phishing-campaign