Device-code phishing campaigns are combining CAPTCHA gates, multi-step SaaS lure chains, encrypted blob-page delivery and source-level text obfuscation to evade automated scanners and reputation checks.
Jul 24, 2026
An active phishing campaign abuses Microsoft's legitimate device-code OAuth flow to capture application tokens instead of passwords. The pages combine trusted sign-in screens with obfuscation, developer-tool detection and debugger traps.
Mar 23, 2026
Several active phishing campaigns use blob URLs to deliver their final pages. By assembling malicious content in browser memory at runtime, these pages can evade network-based analysis.
Oct 2, 2025