Device-code phishing campaigns are combining CAPTCHA gates, multi-step SaaS lure chains, encrypted blob-page delivery and source-level text obfuscation to evade automated scanners and reputation checks.
Jul 24, 2026
An active phishing campaign abuses Microsoft's legitimate device-code OAuth flow to capture application tokens instead of passwords. The pages combine trusted sign-in screens with obfuscation, developer-tool detection and debugger traps.
Mar 23, 2026
Several active phishing campaigns use blob URLs to deliver their final pages. By assembling malicious content in browser memory at runtime, these pages can evade network-based analysis.
Oct 2, 2025
Tracking an active browser-in-the-middle phishing campaign that impersonates Meta and Facebook. The campaign uses copyright-infringement lures and redirect chains to send targets to BitM pages.
Sep 23, 2025