Device Code Phishing Keeps Evolving. Here’s What to Watch For
Cybersecurity Classified by Officially
Device code phishing is still active and evolving. Huntress observed a second 2026 wave tied to BL Networks infrastructure after the earlier Railway campaign, showing attackers continue to adapt a proven token-theft workflow.
The infrastructure may change, but the playbook stays familiar: trusted services and legitimate authentication flows are combined with disposable lure and hosting infrastructure to obtain and replay Microsoft 365 tokens.
Reputation alone isn't a dependable decision point. Defenders should investigate clusters of successful sign-ins from unusual hosting providers or ASNs, especially when the activity is tied to device code flows or repeats across identities and organizations.
Recommended response: restricting device code authentication where it isn't required, investigating suspicious successful logins, and revoking affected sessions and tokens quickly. Huntress' earlier Railway research also recommends Conditional Access controls and Continuous Access Evaluation to reduce exposure after token theft.
Acknowledgments: Special thanks to Rich Mozeleski for his contributions to this investigation and writeup.
Huntress has seen a notable influx in device code phishing attacks in 2026. Earlier this year, we reported a massive wave of device code phishing attacks that stemmed from Railway, a platform-as-a-service built for vibe coding. Starting in April, we also saw attacks from IP addresses linked to a virtual private server (VPS) reseller called BL Networks.
Huntress started seeing suspicious Microsoft 365 authentication activity linked to BL Networks on April 13, 2026, which continues as of this writing. At the beginning of April, we saw all incidents linking back to one offending IP address (216.203.20[.]95).
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/device-code-phishing-evolving-threats
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:55
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/device-code-phishing-evolving-threats