[{"data":1,"prerenderedAt":6756},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":107,"navbar-resource-highlight":181,"trust-badges":225,"solution-nav":246,"fa-icon-solid-faUserSecret":372,"fa-icon-sharp-regular-faLaptopCode":376,"fa-icon-solid-faPlugCircleXmark":378,"fa-icon-sharp-regular-faPuzzlePiece":380,"fa-icon-solid-faFileCircleXmark":382,"fa-icon-solid-faGhost":385,"fa-icon-solid-faQrcode":388,"fa-icon-solid-faCookieBite":390,"fa-icon-sharp-regular-faFishingRod":392,"fa-icon-sharp-regular-faUserSecret":394,"fa-icon-sharp-regular-faRadar":396,"fa-icon-sharp-regular-faSatelliteDish":398,"fa-icon-sharp-regular-faShieldCheck":400,"fa-icon-sharp-regular-faBrainCircuit":402,"fa-icon-solid-faMobileScreenButton":404,"fa-icon-brands-faChrome":406,"fa-icon-solid-faDisplay":408,"fa-icon-solid-faFilter":410,"fa-icon-solid-faCloudArrowUp":412,"blog/authorization-phishing":414,"blog-topics":6355},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"huzkv3ob4qh",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":33,"meta":97,"modelId":101,"name":102,"published":13,"query":103,"testRatio":31,"variations":104,"firstPublished":105,"stageModifiedSincePublish":6,"rev":106},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Struggling to deal with fast-changing attacks? Learn why September 15th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/pyramid-of-pain",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-n2gk66fvrs","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787218042703,{"breakpoints":98,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":99,"lastPreviewUrl":100},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"y0aarzl1gz",[108,144],{"createdBy":32,"createdDate":109,"data":110,"folders":133,"id":134,"lastUpdated":135,"lastUpdatedBy":32,"meta":136,"modelId":138,"name":139,"published":13,"query":140,"stageModifiedSincePublish":6,"testRatio":31,"variations":141,"firstPublished":142,"rev":143},1776247359804,{"link":111,"testimonial":112,"testimonialLink":132,"type":115},{},{"@type":113,"id":114,"model":115,"value":116},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":117,"folders":118,"createdDate":119,"id":114,"name":120,"modelId":121,"published":13,"data":122,"variations":126,"lastUpdated":127,"firstPublished":128,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":129,"rev":131},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":123,"jobTitle":124,"quote":120,"image":125},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":130,"hasAutosaves":19},{"small":17,"medium":16},"dqsseo8tu4t","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":137,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"jz2ycfsbyjf",{"createdBy":32,"createdDate":145,"data":146,"folders":173,"id":174,"lastUpdated":175,"lastUpdatedBy":32,"meta":176,"modelId":138,"name":171,"published":13,"query":178,"stageModifiedSincePublish":6,"testRatio":31,"variations":179,"firstPublished":180,"rev":143},1776255761419,{"description":147,"image":148,"link":149,"testimonial":152,"title":171,"type":172},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":150,"url":151},"Download now","/resources/browser-attacks-report",{"@type":113,"id":153,"model":115,"value":154},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":155,"folders":156,"createdDate":157,"id":153,"name":158,"modelId":121,"published":13,"data":159,"variations":165,"lastUpdated":166,"firstPublished":167,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":168,"rev":170},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":160,"jobTitle":161,"author":162,"qoute":21,"quote":163,"image":164},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":169,"hasAutosaves":19},{"small":17,"medium":16},"6vgcqux4647","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":177,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[182,204],{"createdBy":32,"createdDate":183,"data":184,"folders":194,"id":195,"lastUpdated":196,"lastUpdatedBy":32,"meta":197,"modelId":199,"name":171,"published":13,"query":200,"stageModifiedSincePublish":6,"testRatio":31,"variations":201,"firstPublished":202,"rev":203},1776256900280,{"description":147,"image":148,"link":185,"testimonial":186,"title":171,"type":172},{"text":150,"url":151},{"@type":113,"id":153,"model":115,"value":187},{"query":188,"folders":189,"createdDate":157,"id":153,"name":158,"modelId":121,"published":13,"data":190,"variations":191,"lastUpdated":166,"firstPublished":167,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":192,"rev":170},[],[],{"video":160,"jobTitle":161,"author":162,"qoute":21,"quote":163,"image":164},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":193,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":198,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"ji4hkpzmc6e",{"createdBy":32,"createdDate":205,"data":206,"folders":216,"id":217,"lastUpdated":218,"lastUpdatedBy":32,"meta":219,"modelId":199,"name":221,"published":13,"query":222,"stageModifiedSincePublish":6,"testRatio":31,"variations":223,"firstPublished":224,"rev":203},1776256949234,{"link":207,"testimonial":208,"testimonialLink":132,"type":115},{},{"@type":113,"id":114,"model":115,"value":209},{"query":210,"folders":211,"createdDate":119,"id":114,"name":120,"modelId":121,"published":13,"data":212,"variations":213,"lastUpdated":127,"firstPublished":128,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":214,"rev":131},[],[],{"author":123,"jobTitle":124,"quote":120,"image":125},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":215,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":220,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[226,230,234,238,242],{"title":227,"logo":228,"createdDate":229},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":231,"logo":232,"createdDate":233},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":235,"logo":236,"createdDate":237},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":239,"logo":240,"createdDate":241},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":243,"logo":244,"createdDate":245},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[247,302,347],{"id":248,"label":249,"text":21,"navIcon":250,"items":251},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[252,257,262,267,272,277,282,287,292,297],{"title":253,"text":254,"url":255,"navIcon":256},"Adversary-in-the-Middle","Detect and block AiTM proxies stealing session tokens.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":258,"text":259,"url":260,"navIcon":261},"ClickFix (+Fix variants)","Block attacks that trick users into running malicious code.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":263,"text":264,"url":265,"navIcon":266},"Malicious OAuth integrations","Detect suspicious OAuth consent flows and stop persistent access.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":268,"text":269,"url":270,"navIcon":271},"Malicious browser extensions","Shine a light on risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":273,"text":274,"url":275,"navIcon":276},"Malicious file downloads","Gain visibility into browser downloads and block malicious files.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":278,"text":279,"url":280,"navIcon":281},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":283,"text":284,"url":285,"navIcon":286},"Mobile phishing (QR & SMS)","Detect phishing links delivered via SMS and QR codes.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":288,"text":289,"url":290,"navIcon":291},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":293,"text":294,"url":295,"navIcon":296},"Session hijacking","Detect and block stolen session tokens before attackers get access.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"title":298,"text":299,"url":300,"navIcon":301},"Zero-day phishing","Detect phishing TTPs directly in the browser and stop credential theft.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"id":303,"label":304,"text":21,"navIcon":305,"items":306},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[307,312,317,322,327,332,337,342],{"title":308,"text":309,"url":310,"navIcon":311},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":313,"text":314,"url":315,"navIcon":316},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":318,"text":319,"url":320,"navIcon":321},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":323,"text":324,"url":325,"navIcon":326},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":328,"text":329,"url":330,"navIcon":331},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":333,"text":334,"url":335,"navIcon":336},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":338,"text":339,"url":340,"navIcon":341},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":343,"text":344,"url":345,"navIcon":346},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":348,"label":349,"text":21,"navIcon":350,"items":351},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[352,357,362,367],{"title":353,"text":354,"url":355,"navIcon":356},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":358,"text":359,"url":360,"navIcon":361},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":363,"text":364,"url":365,"navIcon":366},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":368,"text":369,"url":370,"navIcon":371},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":373,"h":374,"d":375},448,512,"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":374,"d":377},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":17,"h":374,"d":379},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":374,"h":374,"d":381},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":383,"h":374,"d":384},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":386,"h":374,"d":387},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":373,"h":374,"d":389},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":374,"h":374,"d":391},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":373,"h":374,"d":393},"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":373,"h":374,"d":395},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":374,"h":374,"d":397},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":374,"h":374,"d":399},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":374,"h":374,"d":401},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":374,"h":374,"d":403},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":386,"h":374,"d":405},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":374,"h":374,"d":407},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":374,"h":374,"d":409},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":374,"h":374,"d":411},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":383,"h":374,"d":413},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":415,"title":416,"authorsCollection":417,"content":427,"extension":1172,"faqItemsCollection":1173,"faqTitle":1362,"featured":6,"hashTags":59,"meta":1363,"metaTitle":1364,"ogImage":59,"postType":1365,"publishedDate":1366,"relatedBlogPostsCollection":1367,"slug":6291,"stem":6292,"subtitle":59,"summary":6293,"synopsis":6304,"sys":6305,"tagsCollection":6308,"topicsCollection":6314,"__hash__":6354},"blog/blog/authorization-phishing.json","Authorization phishing: why attackers stopped targeting the login",{"items":418},[419],{"fullName":420,"firstName":421,"jobTitle":422,"socialLinks":423,"profilePicture":425},"Luke Jennings","Luke","Vice President, R&D",[424],"https://www.linkedin.com/in/luke-jennings-042b5619b/",{"url":426},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"json":428,"links":1087},{"nodeType":429,"data":430,"content":431},"document",{},[432,441,448,468,489,516,547,556,560,569,576,583,589,598,610,629,635,643,679,685,692,699,707,719,737,755,758,766,773,780,788,795,811,823,835,842,854,861,868,874,882,889,896,899,907,914,921,927,951,970,988,994,997,1005,1017,1029,1041,1048,1056],{"nodeType":433,"data":434,"content":435},"paragraph",{},[436],{"nodeType":437,"value":438,"marks":439,"data":440},"text","For most of phishing's history, the objective was simple: steal the credential. Whether through a fake login page twenty years ago or through an attacker in the middle (AiTM) reverse proxy today, the entire attack chain has been oriented around defeating authentication. So defenders have focused on making the login harder to compromise.",[],{},{"nodeType":433,"data":442,"content":443},{},[444],{"nodeType":437,"value":445,"marks":446,"data":447},"This investment is starting to pay off. While MFA as a blanket control is routinely defeated by AiTM attacks (the default phishing method today), phishing-resistant passkeys are used in a relatively small number of logins, but growing steadily each year. And core identity platforms are taking steps to make them the default method. For example, Microsoft is making passkeys the default sign-in method for Entra ID from September 2026, and users stuck on SMS or voice authentication will be force-migrated. ",[],{},{"nodeType":433,"data":449,"content":450},{},[451,455,464],{"nodeType":437,"value":452,"marks":453,"data":454},"AiTM phishing kits remain dominant, but the detection surface is improving — behavioral detections now catch the kit's page behavior regardless of the domain it's hosted on. Authentication controls are genuinely getting harder to beat (though even with passkeys, not impossible, as shown in ",[],{},{"nodeType":456,"data":457,"content":459},"hyperlink",{"uri":458},"https://pushsecurity.com/blog/mfa-downgrade-attacks",[460],{"nodeType":437,"value":461,"marks":462,"data":463},"downgrade attacks",[],{},{"nodeType":437,"value":465,"marks":466,"data":467}," — shown in the video below).",[],{},{"nodeType":433,"data":469,"content":470},{},[471,475,485],{"nodeType":437,"value":472,"marks":473,"data":474},"So it makes sense that attackers are looking for alternatives. In 2026, we’ve seen ",[],{},{"nodeType":456,"data":476,"content":478},{"uri":477},"https://pushsecurity.com/blog/device-code-phishing",[479],{"nodeType":437,"value":480,"marks":481,"data":484},"device code phishing",[482],{"type":483},"underline",{},{"nodeType":437,"value":486,"marks":487,"data":488}," explode into mainstream adoption, with 30+ distinct kits now offering the technique (this number jumps every time we write a new update). ",[],{},{"nodeType":433,"data":490,"content":491},{},[492,496,502,506,512],{"nodeType":437,"value":493,"marks":494,"data":495},"Device code phishing sees the attacker target the authorization layer instead — OAuth consent flows that operate ",[],{},{"nodeType":437,"value":497,"marks":498,"data":501},"after",[499],{"type":500},"italic",{},{"nodeType":437,"value":503,"marks":504,"data":505}," authentication has already succeeded. We're calling this class of attack ",[],{},{"nodeType":437,"value":507,"marks":508,"data":511},"authorization phishing",[509],{"type":510},"bold",{},{"nodeType":437,"value":513,"marks":514,"data":515},", and it represents a structural shift in how identity attacks work.",[],{},{"nodeType":433,"data":517,"content":518},{},[519,523,531,535,543],{"nodeType":437,"value":520,"marks":521,"data":522},"But device code phishing is one technique in a broader shift. ConsentFix, ",[],{},{"nodeType":456,"data":524,"content":526},{"uri":525},"https://pushsecurity.com/blog/consentfix/",[527],{"nodeType":437,"value":528,"marks":529,"data":530},"first discovered by Push in December 2025",[],{},{"nodeType":437,"value":532,"marks":533,"data":534},", has already been ",[],{},{"nodeType":456,"data":536,"content":538},{"uri":537},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[539],{"nodeType":437,"value":540,"marks":541,"data":542},"commoditized into criminal tooling",[],{},{"nodeType":437,"value":544,"marks":545,"data":546},". ",[],{},{"nodeType":548,"data":549,"content":555},"embedded-entry-block",{"target":550},{"sys":551},{"id":552,"type":553,"linkType":554},"3tRYNcUvN7KeFqzaGb2Cmn","Link","Entry",[],{"nodeType":557,"data":558,"content":559},"hr",{},[],{"nodeType":561,"data":562,"content":563},"heading-1",{},[564],{"nodeType":437,"value":565,"marks":566,"data":568},"Authentication phishing vs. authorization phishing",[567],{"type":510},{},{"nodeType":433,"data":570,"content":571},{},[572],{"nodeType":437,"value":573,"marks":574,"data":575},"Authentication phishing targets the login — the moment a user proves their identity. AiTM reverse-proxy kits like Tycoon2FA and Sneaky2FA relay credentials and session tokens in real time, effectively defeating MFA by capturing the authenticated session as it's created. This has been the dominant phishing technique since roughly 2023, and it remains the most common attack we come up against in the wild.",[],{},{"nodeType":433,"data":577,"content":578},{},[579],{"nodeType":437,"value":580,"marks":581,"data":582},"Authorization phishing targets what happens after the login. Instead of stealing a session from the authentication flow, these attacks abuse OAuth authorization mechanisms — consent grants, device code flows, and token exchanges. The attacker never touches the authentication flow at all.",[],{},{"nodeType":548,"data":584,"content":588},{"target":585},{"sys":586},{"id":587,"type":553,"linkType":554},"3ADEkZ8KQKs4ndH1T7PdaX",[],{"nodeType":590,"data":591,"content":592},"heading-2",{},[593],{"nodeType":437,"value":594,"marks":595,"data":597},"Consent phishing: the classic OAuth attack",[596],{"type":510},{},{"nodeType":433,"data":599,"content":600},{},[601,606],{"nodeType":437,"value":602,"marks":603,"data":605},"Consent phishing",[604],{"type":510},{},{"nodeType":437,"value":607,"marks":608,"data":609}," is the oldest of the three, and the classic OAuth attack. The attacker creates a malicious third-party application and tricks the user into granting it permissions via an OAuth consent prompt. The app then uses those permissions to access the user's data via API.",[],{},{"nodeType":433,"data":611,"content":612},{},[613,617,625],{"nodeType":437,"value":614,"marks":615,"data":616},"Identity providers have substantially hardened their default configurations against consent phishing. Most platforms today do not allow users to consent to apps that have not already been admin-consented into the tenant. For example, ",[],{},{"nodeType":456,"data":618,"content":620},{"uri":619},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[621],{"nodeType":437,"value":622,"marks":623,"data":624},"Microsoft now blocks unverified third-party app consent by default",[],{},{"nodeType":437,"value":626,"marks":627,"data":628},", as does Google, and GitHub restricts OAuth apps to org-owner approval. ",[],{},{"nodeType":548,"data":630,"content":634},{"target":631},{"sys":632},{"id":633,"type":553,"linkType":554},"1KJGoZABIAsuXG5QjBVWOY",[],{"nodeType":590,"data":636,"content":637},{},[638],{"nodeType":437,"value":639,"marks":640,"data":642},"Device code phishing: the breakout threat of 2026",[641],{"type":510},{},{"nodeType":433,"data":644,"content":645},{},[646,651,655,663,667,675],{"nodeType":437,"value":647,"marks":648,"data":650},"Device code phishing",[649],{"type":510},{},{"nodeType":437,"value":652,"marks":653,"data":654}," targets a different OAuth flow entirely: the ",[],{},{"nodeType":456,"data":656,"content":658},{"uri":657},"https://pushsecurity.com/blog/device-code-phishing/",[659],{"nodeType":437,"value":660,"marks":661,"data":662},"RFC 8628 device authorization grant",[],{},{"nodeType":437,"value":664,"marks":665,"data":666},", originally designed for input-constrained devices like smart TVs and IoT hardware. The attacker generates a code, delivers it to the victim via a phishing page that auto-polls for a fresh code on page load (which can arrive over email, Teams messages, LinkedIn DMs, voice calls, malvertising, or compromised websites), and the victim enters the code on the real device code for the target app. In the wild this is usually Microsoft, but last year's ",[],{},{"nodeType":456,"data":668,"content":670},{"uri":669},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[671],{"nodeType":437,"value":672,"marks":673,"data":674},"ShinyHunters",[],{},{"nodeType":437,"value":676,"marks":677,"data":678}," campaign saw Salesforce targeted too.",[],{},{"nodeType":548,"data":680,"content":684},{"target":681},{"sys":682},{"id":683,"type":553,"linkType":554},"79aVRaPAuAaiNZvTspbmHK",[],{"nodeType":433,"data":686,"content":687},{},[688],{"nodeType":437,"value":689,"marks":690,"data":691},"This grants the attacker an access token scoped to whichever application was targeted, and critically, because device code phishing targets apps that are already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that have made traditional consent phishing harder. ",[],{},{"nodeType":433,"data":693,"content":694},{},[695],{"nodeType":437,"value":696,"marks":697,"data":698},"In Microsoft environments, the impact can extend beyond API access — if the attacker targets the Microsoft Authentication Broker, they can register a virtual device against the victim's account and escalate to a full Primary Refresh Token, gaining an interactive SSO-enabled session that can laterally move across any SSO-joined application.",[],{},{"nodeType":590,"data":700,"content":701},{},[702],{"nodeType":437,"value":703,"marks":704,"data":706},"ConsentFix: the new ClickFix-OAuth hybrid",[705],{"type":510},{},{"nodeType":433,"data":708,"content":709},{},[710,715],{"nodeType":437,"value":711,"marks":712,"data":714},"ConsentFix",[713],{"type":510},{},{"nodeType":437,"value":716,"marks":717,"data":718}," occupies an interesting middle ground. It targets the same OAuth flow as consent phishing — the authorization code grant (RFC 6749) — but it targets pre-approved first-party apps rather than attacker-created third-party apps, which means the consent restrictions that shut down traditional consent phishing don't apply.",[],{},{"nodeType":433,"data":720,"content":721},{},[722,725,733],{"nodeType":437,"value":21,"marks":723,"data":724},[],{},{"nodeType":456,"data":726,"content":727},{"uri":525},[728],{"nodeType":437,"value":729,"marks":730,"data":732},"First observed in Russia-linked APT29 campaigns in late 2025",[731],{"type":483},{},{"nodeType":437,"value":734,"marks":735,"data":736},", the original attacks appeared on compromised websites and were tightly targeted — the attack only activated for specific email domains, allowing non-targets to use the site as normal. ConsentFix combines ClickFix-style clipboard injection with OAuth consent abuse, exploiting apps that use a localhost redirect URI as part of the handshake to capture authorization codes that are usually picked up by a server-side callback.",[],{},{"nodeType":433,"data":738,"content":739},{},[740,744,751],{"nodeType":437,"value":741,"marks":742,"data":743},"Push detected and blocked ConsentFix the first time it was seen in the wild, and within months of disclosure, a ",[],{},{"nodeType":456,"data":745,"content":746},{"uri":537},[747],{"nodeType":437,"value":748,"marks":749,"data":750},"criminal ConsentFix toolkit",[],{},{"nodeType":437,"value":752,"marks":753,"data":754}," appeared on the XSS forum, making the technique more widely available.",[],{},{"nodeType":557,"data":756,"content":757},{},[],{"nodeType":561,"data":759,"content":760},{},[761],{"nodeType":437,"value":762,"marks":763,"data":765},"What defenders think works (and what actually does)",[764],{"type":510},{},{"nodeType":433,"data":767,"content":768},{},[769],{"nodeType":437,"value":770,"marks":771,"data":772},"As we've already established, authentication controls like passkeys have no impact on these attacks, which can come as a surprise for those that have bought into the \"phishing-resistant\" tag of passkeys at face value. That isn't to diminish their value, the passkey isn't phished in this scenario, it's just being circumvented.",[],{},{"nodeType":433,"data":774,"content":775},{},[776],{"nodeType":437,"value":777,"marks":778,"data":779},"Passkeys remain the strongest available protection against AiTM and credential theft. But they address a different layer of the problem, and treating them as a complete answer to phishing creates a dangerous blind spot as attackers shift to authorization-layer techniques.",[],{},{"nodeType":590,"data":781,"content":782},{},[783],{"nodeType":437,"value":784,"marks":785,"data":787},"Evaluating post-authentication controls like Conditional Access Policies",[786],{"type":510},{},{"nodeType":433,"data":789,"content":790},{},[791],{"nodeType":437,"value":792,"marks":793,"data":794},"Conditional access policies are the primary layer of defense cited against these authorization-layer attacks. We tested the most cited conditional access controls against both device code phishing and ConsentFix, and the results vary significantly.",[],{},{"nodeType":433,"data":796,"content":797},{},[798,802,807],{"nodeType":437,"value":799,"marks":800,"data":801},"Since the policy for ",[],{},{"nodeType":437,"value":803,"marks":804,"data":806},"require phishing-resistant authentication",[805],{"type":510},{},{"nodeType":437,"value":808,"marks":809,"data":810}," pertains to the enforcement of passkey-based logins, this has no impact here as we discussed above.",[],{},{"nodeType":433,"data":812,"content":813},{},[814,819],{"nodeType":437,"value":815,"marks":816,"data":818},"Block device code flow",[817],{"type":510},{},{"nodeType":437,"value":820,"marks":821,"data":822}," is the most direct control, and it works — but only against device code phishing, not ConsentFix. It also blocks legitimate device code use cases (Azure CLI, conference room hardware, developer tooling), so organizations with real device code dependencies need per-user group or per-app exceptions that create potential gaps.",[],{},{"nodeType":433,"data":824,"content":825},{},[826,831],{"nodeType":437,"value":827,"marks":828,"data":830},"Require compliant device",[829],{"type":510},{},{"nodeType":437,"value":832,"marks":833,"data":834}," is the most effective broad control. Device code flows can't present the TPM-bound proof-of-possession that device compliance requires, so they're blocked outright. However, as above, if you have legitimate uses for device code logins in your environment, you’d need to implement exceptions to this policy. ",[],{},{"nodeType":433,"data":836,"content":837},{},[838],{"nodeType":437,"value":839,"marks":840,"data":841},"ConsentFix, on the other hand, passes through this check. BYOD scenarios also create gaps — personal devices authenticating via browser without a Primary Refresh Token won't satisfy the compliance requirement either, for legitimate and malicious flows alike.",[],{},{"nodeType":433,"data":843,"content":844},{},[845,850],{"nodeType":437,"value":846,"marks":847,"data":849},"Token protection",[848],{"type":510},{},{"nodeType":437,"value":851,"marks":852,"data":853},", currently in preview, binds refresh tokens to the device's TPM. It performed better in testing than expected for some ConsentFix scenarios — depending on the scopes requested and the target app — but it doesn't apply to all apps and resources.",[],{},{"nodeType":433,"data":855,"content":856},{},[857],{"nodeType":437,"value":858,"marks":859,"data":860},"Conditional access can be tricky to manage, however, particularly for larger organizations. User groups need maintaining, new apps need scoping, exceptions accumulate, and policies interact in ways that aren't always obvious from the admin console. It's easy to accidentally leave policies in report-only mode (I found this myself during testing) or create exceptions for specific apps that inadvertently open the authorization attack surface. And ticking the box doesn't tell you whether it works in practice.",[],{},{"nodeType":433,"data":862,"content":863},{},[864],{"nodeType":437,"value":865,"marks":866,"data":867},"Microsoft is taking additional steps to reduce the attack surface here — device code flow is blocked by default in new tenants, and they appear to be locking down apps and reply URLs to reduce the ConsentFix attack surface, including adding explicit \"this might be a phishing attack\" warnings on certain reply URLs used in ConsentFix scenarios. But the gap between a default deployment and a hardened one remains wide.",[],{},{"nodeType":548,"data":869,"content":873},{"target":870},{"sys":871},{"id":872,"type":553,"linkType":554},"3FguCE9HzDsj94TgRzZSk6",[],{"nodeType":590,"data":875,"content":876},{},[877],{"nodeType":437,"value":878,"marks":879,"data":881},"What about blocking the apps themselves?",[880],{"type":510},{},{"nodeType":433,"data":883,"content":884},{},[885],{"nodeType":437,"value":886,"marks":887,"data":888},"The challenge is that the apps being abused aren't malicious — they're legitimate first-party Microsoft applications like Azure CLI, Microsoft Office, and Teams. They exist in every Entra tenant by default, are pre-consented with broad permissions, and can't simply be removed.",[],{},{"nodeType":433,"data":890,"content":891},{},[892],{"nodeType":437,"value":893,"marks":894,"data":895},"An admin can toggle \"assignment required\" on a service principal and restrict which users can authenticate through that app, but that means pre-creating and managing user assignments for every first-party app that could be targeted. Over-restricting broadly used apps like Teams or Office may break core workflows.",[],{},{"nodeType":557,"data":897,"content":898},{},[],{"nodeType":561,"data":900,"content":901},{},[902],{"nodeType":437,"value":903,"marks":904,"data":906},"The future of authorization phishing",[905],{"type":510},{},{"nodeType":433,"data":908,"content":909},{},[910],{"nodeType":437,"value":911,"marks":912,"data":913},"Several developments will determine how fast this category matures. Device code phishing is a core technique now, supported by most PhaaS vendors and bolted onto AiTM kits. ConsentFix criminal adoption is still early but could follow suit at any time. ",[],{},{"nodeType":433,"data":915,"content":916},{},[917],{"nodeType":437,"value":918,"marks":919,"data":920},"Non-Microsoft targets are the logical next step — device code phishing has already been demonstrated against Salesforce, and I showed off GitHub targeting in my recent webinar. Any platform that supports the authorization code grant with localhost redirect or the device authorization grant is a potential target. ",[],{},{"nodeType":548,"data":922,"content":926},{"target":923},{"sys":924},{"id":925,"type":553,"linkType":554},"UIOVxK4yPURUu8slsKWMu",[],{"nodeType":433,"data":928,"content":929},{},[930,935,939,947],{"nodeType":437,"value":931,"marks":932,"data":934},"But OAuth is complex, and the authorization mechanisms that have been abused so far likely don't represent the full attack surface. ",[933],{"type":510},{},{"nodeType":437,"value":936,"marks":937,"data":938},"Everything discussed so far has been initial access, but OAuth is also powerful at the persistence and lateral movement layers — an attacker who plants a malicious OAuth grant during a compromise has a ",[],{},{"nodeType":456,"data":940,"content":942},{"uri":941},"https://pushsecurity.com/blog/nearly-invisible-attack-chain/",[943],{"nodeType":437,"value":944,"marks":945,"data":946},"stealthy persistence mechanism",[],{},{"nodeType":437,"value":948,"marks":949,"data":950}," that survives credential resets and password changes, and can be extremely difficult to detect. As authorization phishing matures, we expect these post-compromise OAuth techniques to become more common too.",[],{},{"nodeType":433,"data":952,"content":953},{},[954,958,966],{"nodeType":437,"value":955,"marks":956,"data":957},"The ",[],{},{"nodeType":456,"data":959,"content":961},{"uri":960},"https://pushsecurity.com/blog/openai-poisoned-tenant-attack",[962],{"nodeType":437,"value":963,"marks":964,"data":965},"poisoned tenant attack surface",[],{},{"nodeType":437,"value":967,"marks":968,"data":969}," also remains largely undefended, which could see more typical consent phishing come back around. Historically, consent phishing involved an attacker creating a malicious app and inviting their targets to it. But you can just set up a tenant on a legit SaaS app and use that instead.",[],{},{"nodeType":433,"data":971,"content":972},{},[973,977,984],{"nodeType":437,"value":974,"marks":975,"data":976},"Most SaaS platforms let anyone create a workspace impersonating any organization, and few offer controls for admins to restrict which tenants their employees can join. We ",[],{},{"nodeType":456,"data":978,"content":979},{"uri":960},[980],{"nodeType":437,"value":981,"marks":982,"data":983},"recently experienced this directly",[],{},{"nodeType":437,"value":985,"marks":986,"data":987}," when an attacker created a fake OpenAI organization under our company's name and invited specific employees to join it.",[],{},{"nodeType":548,"data":989,"content":993},{"target":990},{"sys":991},{"id":992,"type":553,"linkType":554},"1YPMilWhyTSV860PCFXxmx",[],{"nodeType":557,"data":995,"content":996},{},[],{"nodeType":561,"data":998,"content":999},{},[1000],{"nodeType":437,"value":1001,"marks":1002,"data":1004},"What defenders should actually do",[1003],{"type":510},{},{"nodeType":433,"data":1006,"content":1007},{},[1008,1013],{"nodeType":437,"value":1009,"marks":1010,"data":1012},"First, test your defenses against authorization attacks specifically.",[1011],{"type":510},{},{"nodeType":437,"value":1014,"marks":1015,"data":1016}," Don't assume that MFA, passkeys, or conditional access policies handle this. Run a device code phishing simulation against your environment and verify that your conditional access configuration actually blocks it. Test ConsentFix scenarios. If your controls rely on configuration assumptions you haven't validated, you have a gap.",[],{},{"nodeType":433,"data":1018,"content":1019},{},[1020,1025],{"nodeType":437,"value":1021,"marks":1022,"data":1024},"Second, don't treat this as exclusively a Microsoft problem. ",[1023],{"type":510},{},{"nodeType":437,"value":1026,"marks":1027,"data":1028},"Device code phishing can work against several apps. GitHub exposes broad scopes including full repository access and uses device code as the default CLI sign-in method — meaning developers encounter legitimate device code flows routinely, making phishing lures harder to distinguish from normal workflow. ConsentFix-style attacks targeting authorization code grants with localhost redirects could also expand beyond Microsoft as the technique matures.",[],{},{"nodeType":433,"data":1030,"content":1031},{},[1032,1037],{"nodeType":437,"value":1033,"marks":1034,"data":1036},"Third, update your security awareness training.",[1035],{"type":510},{},{"nodeType":437,"value":1038,"marks":1039,"data":1040}," Most employees have no concept of authorization phishing — it doesn't look or feel like any phishing that they're used to. There's no suspicious login page, no credential entry on an unfamiliar domain. Traditional awareness training does not prepare users for this.",[],{},{"nodeType":433,"data":1042,"content":1043},{},[1044],{"nodeType":437,"value":1045,"marks":1046,"data":1047},"But to detect and block these attacks as they happen, you need to be in the browser. Push detects and blocks authorization attacks in real time, when the user is tricked into performing the malicious consent grant. We detected ConsentFix the first time it appeared in the wild, before any other vendor, and device code phishing detection has been live since the technique first entered mainstream use.",[],{},{"nodeType":590,"data":1049,"content":1050},{},[1051],{"nodeType":437,"value":1052,"marks":1053,"data":1055},"Watch the research",[1054],{"type":510},{},{"nodeType":433,"data":1057,"content":1058},{},[1059,1063,1071,1075,1083],{"nodeType":437,"value":1060,"marks":1061,"data":1062},"I recently talked about authorization phishing at ",[],{},{"nodeType":456,"data":1064,"content":1066},{"uri":1065},"https://bsideslv.org/schedule3#PA",[1067],{"nodeType":437,"value":1068,"marks":1069,"data":1070},"BSides Las Vegas 2026",[],{},{"nodeType":437,"value":1072,"marks":1073,"data":1074},", walking through live demonstrations of device code phishing (including against passkey-protected accounts), ConsentFix, and conditional access policy bypass testing. The full talk is available to ",[],{},{"nodeType":456,"data":1076,"content":1078},{"uri":1077},"https://www.youtube.com/live/9wx9Nt3JWSs",[1079],{"nodeType":437,"value":1080,"marks":1081,"data":1082},"watch on YouTube",[],{},{"nodeType":437,"value":1084,"marks":1085,"data":1086}," (starts at 27:12).",[],{},{"entries":1088},{"hyperlink":1089,"inline":1090,"block":1091},[],[],[1092,1107,1133,1147,1153,1161,1165],{"sys":1093,"__typename":1094,"content":1095,"name":1106,"title":59},{"id":552},"InsightTextBlockComponent",{"json":1096},{"nodeType":429,"data":1097,"content":1098},{},[1099],{"nodeType":433,"data":1100,"content":1101},{},[1102],{"nodeType":437,"value":1103,"marks":1104,"data":1105},"In this blog post, we’ll talk about the different authorization attacks used by attackers in the wild and what this means for security teams looking to detect and block these attacks.",[],{},"Authorization phishing IB2",{"sys":1108,"__typename":1094,"content":1109,"name":1132,"title":59},{"id":587},{"json":1110},{"data":1111,"content":1112,"nodeType":429},{},[1113],{"data":1114,"content":1115,"nodeType":433},{},[1116,1120,1128],{"data":1117,"marks":1118,"value":1119,"nodeType":437},{},[],"Three techniques currently fall under the authorization phishing umbrella. Most of them are exactly new, either — Push cataloged consent phishing and device code phishing in the ",{"data":1121,"content":1123,"nodeType":456},{"uri":1122},"https://pushsecurity.com/resources/browser-identity-attacks-matrix",[1124],{"data":1125,"marks":1126,"value":1127,"nodeType":437},{},[],"Browser & Identity Attacks Matrix",{"data":1129,"marks":1130,"value":1131,"nodeType":437},{},[]," back in 2023. What's changed in 2026 is that they've moved from isolated, targeted operations to widespread adoption across the phishing-as-a-service ecosystem.","Authorization phishing IB1",{"sys":1134,"__typename":1094,"content":1135,"name":1146,"title":59},{"id":633},{"json":1136},{"nodeType":429,"data":1137,"content":1138},{},[1139],{"nodeType":433,"data":1140,"content":1141},{},[1142],{"nodeType":437,"value":1143,"marks":1144,"data":1145},"And even if you can get in, once a malicious app is flagged, it's burned — and unlike domains and IP addresses, it's not easy to rotate. The vendor can ban the app, ban the entire tenant associated with it, and block the attacker's registration infrastructure. Setting up new apps at scale requires new verified tenants, which makes the economics of consent phishing significantly worse than other techniques. These controls are the main reason we don't see it much in the wild anymore.",[],{},"Authorization phishing IB3",{"sys":1148,"__typename":1149,"title":1150,"arcadeDemoUrl":1151,"playText":1152},{"id":683},"ArcadeDemo","Device code phishing: In the wild examples","https://demo.arcade.software/Fx5XuPm0JCceQRgAvH9C?embed","2 mins",{"sys":1154,"__typename":1155,"title":1156,"caption":1156,"layoutMode":59,"file":1157},{"id":872},"Image","Native client warning displayed for ConsentFix attacks requesting certain scope and app combinations. ",{"url":1158,"width":1159,"height":1160},"https://images.ctfassets.net/y1cdw1ablpvd/3bV6Kt6BQqseSGPRmNeqYT/e93466e14eeb45fb9d07fa135d6b80e4/nativeclient_warning.png",1278,987,{"sys":1162,"__typename":1149,"title":1163,"arcadeDemoUrl":1164,"playText":1152},{"id":925},"Device Code Phishing Demo: GitHub","https://demo.arcade.software/8WVq7zlbQYahwpDLs6ly?embed",{"sys":1166,"__typename":1155,"title":1167,"caption":1167,"layoutMode":59,"file":1168},{"id":992},"\"Invite accepted\" confirmation page for the poisoned OpenAI tenant.",{"url":1169,"width":1170,"height":1171},"https://images.ctfassets.net/y1cdw1ablpvd/38N7FnCMSQz519ZXQfpXo4/f848d30b238b943a47efa29d12b68b87/image5.png",1999,1031,"json",{"items":1174},[1175,1188,1201,1214,1227,1240,1253,1287,1321],{"answer":1176,"question":1187},{"json":1177},{"nodeType":429,"data":1178,"content":1179},{},[1180],{"nodeType":433,"data":1181,"content":1182},{},[1183],{"nodeType":437,"value":1184,"marks":1185,"data":1186},"Authorization phishing is a category of phishing attacks that target OAuth authorization flows rather than the authentication (login) process. Instead of stealing credentials or session tokens, authorization phishing tricks users into granting attacker-controlled applications access to their accounts through legitimate OAuth consent prompts or device code flows. The user authenticates normally — on the real identity provider, with their real credentials and MFA — and the attack exploits the authorization decision that follows.",[],{},"What is authorization phishing?",{"answer":1189,"question":1200},{"json":1190},{"nodeType":429,"data":1191,"content":1192},{},[1193],{"nodeType":433,"data":1194,"content":1195},{},[1196],{"nodeType":437,"value":1197,"marks":1198,"data":1199},"Authentication phishing attacks the login — the moment a user proves their identity. Techniques like AiTM (adversary-in-the-middle) phishing use reverse-proxy kits to intercept credentials and session tokens during the authentication flow. Authorization phishing attacks what happens after the login. The user authenticates legitimately, and the attacker abuses OAuth mechanisms (consent grants, device code flows, token exchanges) to obtain access tokens. The key difference: authentication phishing defeats MFA by proxying the login and intercepting the session token, while authorization phishing makes MFA irrelevant because the authentication succeeds normally.",[],{},"What's the difference between authentication phishing and authorization phishing?",{"answer":1202,"question":1213},{"json":1203},{"nodeType":429,"data":1204,"content":1205},{},[1206],{"nodeType":433,"data":1207,"content":1208},{},[1209],{"nodeType":437,"value":1210,"marks":1211,"data":1212},"No. All forms of MFA — including passkeys, FIDO2 keys, authenticator apps, and SMS codes — protect the authentication flow. Authorization phishing targets the authorization layer, which operates after authentication has already succeeded. The user completes MFA normally, and the attack exploits the subsequent OAuth consent or device code flow. Passkeys remain the strongest defense against authentication phishing (AiTM, credential theft), but they don't address authorization-layer attacks.",[],{},"Can MFA and passkeys stop authorization phishing?",{"answer":1215,"question":1226},{"json":1216},{"nodeType":429,"data":1217,"content":1218},{},[1219],{"nodeType":433,"data":1220,"content":1221},{},[1222],{"nodeType":437,"value":1223,"marks":1224,"data":1225},"Some conditional access policies can block device code phishing, but effectiveness is highly configuration-dependent. \"Block device code flow\" is effective but also blocks legitimate use cases. \"Require compliant device\" blocks device code phishing because the flow can't present device compliance proofs, but doesn't stop ConsentFix. \"Token protection\" (currently in preview) has limited applicability. \"Require phishing-resistant authentication\" is not applicable because the authentication in device code phishing is already legitimate. The gap between a default conditional access deployment and a hardened one is significant.",[],{},"Can conditional access policies stop device code phishing?",{"answer":1228,"question":1239},{"json":1229},{"nodeType":429,"data":1230,"content":1231},{},[1232],{"nodeType":433,"data":1233,"content":1234},{},[1235],{"nodeType":437,"value":1236,"marks":1237,"data":1238},"ConsentFix is harder to block with conditional access because it uses the standard authorization code grant flow rather than the device code flow. \"Block device code flow\" doesn't apply. \"Require compliant device\" doesn't stop ConsentFix. \"Token protection\" mitigates some ConsentFix scenarios depending on scopes requested, but it's in preview and limited in scope. Microsoft appears to be reducing the ConsentFix attack surface by locking down apps and reply URLs, but there is currently no single conditional access policy that reliably blocks all ConsentFix variants.",[],{},"Can conditional access policies stop ConsentFix?",{"answer":1241,"question":1252},{"json":1242},{"nodeType":429,"data":1243,"content":1244},{},[1245],{"nodeType":433,"data":1246,"content":1247},{},[1248],{"nodeType":437,"value":1249,"marks":1250,"data":1251},"Authorization phishing detection requires visibility at the browser layer, where the OAuth consent and device code flows actually execute. This includes monitoring device code authorization pages for suspicious activity, capturing OAuth consent flows (client ID, scopes requested, authorization server, outcome), and detecting browser-native attacks like ConsentFix that combine clipboard injection with OAuth abuse. Network-layer and endpoint-layer tools don't have visibility into these browser-rendered authorization flows.",[],{},"How do you detect authorization phishing?",{"answer":1254,"question":1286},{"json":1255},{"nodeType":429,"data":1256,"content":1257},{},[1258,1265,1272,1279],{"nodeType":433,"data":1259,"content":1260},{},[1261],{"nodeType":437,"value":1262,"marks":1263,"data":1264},"No. Email gateways won't catch it — a device code phishing lure asks the user to visit a legitimate URL (like microsoft.com/devicelogin) and enter a code. There's no malicious link, no credential-harvesting page, and no suspicious attachment for the gateway to flag. The pages and infrastructure used as part of these campaigns are frequently rotated to evade blocklists. ",[],{},{"nodeType":433,"data":1266,"content":1267},{},[1268],{"nodeType":437,"value":1269,"marks":1270,"data":1271},"SWGs inspect network traffic and enforce access policies, but the authorization flow happens on the real identity provider's domain over a legitimate connection — indistinguishable from a normal sign-in. ",[],{},{"nodeType":433,"data":1273,"content":1274},{},[1275],{"nodeType":437,"value":1276,"marks":1277,"data":1278},"EDR won't see it either, because the entire attack plays out in the browser via standard web requests — no malicious payload touches the filesystem or triggers OS-level detection. These tools are built to detect authentication phishing — malicious URLs, cloned login pages, known-bad infrastructure — and authorization phishing doesn't produce any of those artifacts. ",[],{},{"nodeType":433,"data":1280,"content":1281},{},[1282],{"nodeType":437,"value":1283,"marks":1284,"data":1285},"Browser-layer detection closes the gap, because it has visibility into the authorization flow itself, tab metadata, and page context that makes bad activity identifiable from normal behavior.",[],{},"Can I detect authorization attacks with my email gateway, SWG, or EDR?",{"answer":1288,"question":1320},{"json":1289},{"nodeType":429,"data":1290,"content":1291},{},[1292,1299,1306,1313],{"nodeType":433,"data":1293,"content":1294},{},[1295],{"nodeType":437,"value":1296,"marks":1297,"data":1298},"Yes, in Microsoft environments. Entra ID conditional access includes a \"block device code flow\" policy that prevents device code authorizations outright, and Microsoft now recommends enabling it for any tenant that hasn't used the flow in the past 25 days. ",[],{},{"nodeType":433,"data":1300,"content":1301},{},[1302],{"nodeType":437,"value":1303,"marks":1304,"data":1305},"The main operational cost is that Azure CLI, developer tooling, and conference room hardware often depend on device code flow, so developer-heavy organizations may need exclusions that increase susceptibility to this technique. ",[],{},{"nodeType":433,"data":1307,"content":1308},{},[1309],{"nodeType":437,"value":1310,"marks":1311,"data":1312},"\"Require compliant device\" also blocks device code phishing indirectly, since the flow can't present the TPM-bound proof that compliance requires. Two important caveats: blocking device code flow doesn't block ConsentFix or other authorization code grant attacks, so it's a partial solution to the broader authorization phishing category. ",[],{},{"nodeType":433,"data":1314,"content":1315},{},[1316],{"nodeType":437,"value":1317,"marks":1318,"data":1319},"Outside Microsoft, options are more limited — Google mitigates the risk by restricting which scopes are available through device code, but GitHub and other platforms that support the flow don't offer equivalent blocking controls, leaving you reliant on monitoring and detection rather than prevention.",[],{},"Can you block device code phishing?",{"answer":1322,"question":1361},{"json":1323},{"nodeType":429,"data":1324,"content":1325},{},[1326,1333,1340,1347,1354],{"nodeType":433,"data":1327,"content":1328},{},[1329],{"nodeType":437,"value":1330,"marks":1331,"data":1332},"The attack isn't Microsoft-exclusive, but the exposure varies across different platforms. Microsoft has the broadest exposure because of unrestricted scopes, reusable first-party client IDs, and FOCI token exchange. This, combined with the prevalence of Microsoft, is why the overwhelming majority of observed attacks target Entra ID.",[],{},{"nodeType":433,"data":1334,"content":1335},{},[1336],{"nodeType":437,"value":1337,"marks":1338,"data":1339},"GitHub is also an obvious target: device code flow is the default CLI sign-in method, and broad scopes including full repository access are available, though the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",[],{},{"nodeType":433,"data":1341,"content":1342},{},[1343],{"nodeType":437,"value":1344,"marks":1345,"data":1346},"Google is lower risk for device code phishing specifically — Google explicitly limits which scopes are accessible through the device code flow, making Gmail, Calendar, and most Workspace APIs unavailable through this mechanism. ",[],{},{"nodeType":433,"data":1348,"content":1349},{},[1350],{"nodeType":437,"value":1351,"marks":1352,"data":1353},"Salesforce and AWS also support the flow. However Salesforce implemented changes to app approvals and permissions following the large-scale campaign in 2025 to reduce the scope for abuse in future.",[],{},{"nodeType":433,"data":1355,"content":1356},{},[1357],{"nodeType":437,"value":1358,"marks":1359,"data":1360},"If your environment relies on any platform that supports OAuth device authorization grants or authorization code grants with localhost redirect URIs, the attack surface exists.",[],{},"We're not a Microsoft shop — do we still need to worry about authorization phishing?","Authorization Phishing: Frequently Asked Questions",{},"How authorization phishing attacks bypass MFA and passkeys","threat-research","2026-08-24T00:00:00.000Z",{"items":1368},[1369,2692,5712],{"__typename":1370,"sys":1371,"content":1373,"title":2670,"synopsis":2671,"hashTags":59,"publishedDate":2672,"slug":2673,"tagsCollection":2674,"authorsCollection":2684},"BlogPosts",{"id":1372},"vLb3RhwYt7Xc6mkX3pWyI",{"json":1374},{"nodeType":429,"data":1375,"content":1376},{},[1377,1384,1387,1395,1425,1433,1439,1470,1585,1626,1634,1689,1720,1726,1729,1737,1744,1752,1769,1824,1830,1837,1855,1861,1868,1874,1881,1887,1894,1900,1908,1951,1982,2001,2031,2039,2070,2101,2132,2140,2147,2166,2220,2251,2259,2277,2320,2323,2331,2338,2345,2363,2369,2376,2490,2533,2541,2560,2567,2570,2578,2585,2628,2635,2638,2645,2652],{"nodeType":433,"data":1378,"content":1379},{},[1380],{"nodeType":437,"value":1381,"marks":1382,"data":1383},"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",[],{},{"nodeType":557,"data":1385,"content":1386},{},[],{"nodeType":561,"data":1388,"content":1389},{},[1390],{"nodeType":437,"value":1391,"marks":1392,"data":1394},"The SLH playbook becomes the industry standard",[1393],{"type":510},{},{"nodeType":433,"data":1396,"content":1397},{},[1398,1402,1410,1414,1421],{"nodeType":437,"value":1399,"marks":1400,"data":1401},"Criminals associated with \"The Com,\" broadly known as the ",[],{},{"nodeType":456,"data":1403,"content":1405},{"uri":1404},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[1406],{"nodeType":437,"value":1407,"marks":1408,"data":1409},"Scattered Lapsus$ Hunters",[],{},{"nodeType":437,"value":1411,"marks":1412,"data":1413}," collective, have spent the past three years establishing a playbook ",[],{},{"nodeType":456,"data":1415,"content":1416},{"uri":669},[1417],{"nodeType":437,"value":1418,"marks":1419,"data":1420},"focused on identity compromise and cloud data theft",[],{},{"nodeType":437,"value":1422,"marks":1423,"data":1424}," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",[],{},{"nodeType":433,"data":1426,"content":1427},{},[1428],{"nodeType":437,"value":1429,"marks":1430,"data":1432},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",[1431],{"type":510},{},{"nodeType":548,"data":1434,"content":1438},{"target":1435},{"sys":1436},{"id":1437,"type":553,"linkType":554},"3hODobO3VJr3LvbXkzso8I",[],{"nodeType":433,"data":1440,"content":1441},{},[1442,1446,1454,1458,1466],{"nodeType":437,"value":1443,"marks":1444,"data":1445},"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",[],{},{"nodeType":456,"data":1447,"content":1449},{"uri":1448},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams",[1450],{"nodeType":437,"value":1451,"marks":1452,"data":1453},"tricking help desks into performing account resets",[],{},{"nodeType":437,"value":1455,"marks":1456,"data":1457},". This year, they've switched to using voice-based lures in tandem with ",[],{},{"nodeType":456,"data":1459,"content":1461},{"uri":1460},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign",[1462],{"nodeType":437,"value":1463,"marks":1464,"data":1465},"browser-based phishing payloads",[],{},{"nodeType":437,"value":1467,"marks":1468,"data":1469}," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",[],{},{"nodeType":433,"data":1471,"content":1472},{},[1473,1477,1485,1489,1497,1501,1509,1513,1521,1525,1533,1537,1545,1549,1557,1561,1569,1573,1581],{"nodeType":437,"value":1474,"marks":1475,"data":1476},"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",[],{},{"nodeType":456,"data":1478,"content":1480},{"uri":1479},"https://www.securityweek.com/panera-bread-data-breach-linked-to-shinyhunters-sso-campaign/",[1481],{"nodeType":437,"value":1482,"marks":1483,"data":1484},"Panera Bread",[],{},{"nodeType":437,"value":1486,"marks":1487,"data":1488}," (~14M records), ",[],{},{"nodeType":456,"data":1490,"content":1492},{"uri":1491},"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",[1493],{"nodeType":437,"value":1494,"marks":1495,"data":1496},"Match Group",[],{},{"nodeType":437,"value":1498,"marks":1499,"data":1500}," (Hinge, Tinder, OkCupid; 10M+ records), ",[],{},{"nodeType":456,"data":1502,"content":1504},{"uri":1503},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[1505],{"nodeType":437,"value":1506,"marks":1507,"data":1508},"Betterment",[],{},{"nodeType":437,"value":1510,"marks":1511,"data":1512}," (~20M records), ",[],{},{"nodeType":456,"data":1514,"content":1516},{"uri":1515},"https://www.bleepingcomputer.com/news/security/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/",[1517],{"nodeType":437,"value":1518,"marks":1519,"data":1520},"Odido",[],{},{"nodeType":437,"value":1522,"marks":1523,"data":1524}," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",[],{},{"nodeType":456,"data":1526,"content":1528},{"uri":1527},"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/",[1529],{"nodeType":437,"value":1530,"marks":1531,"data":1532},"ADT",[],{},{"nodeType":437,"value":1534,"marks":1535,"data":1536}," (5.5M records), ",[],{},{"nodeType":456,"data":1538,"content":1540},{"uri":1539},"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/",[1541],{"nodeType":437,"value":1542,"marks":1543,"data":1544},"Charter Communications",[],{},{"nodeType":437,"value":1546,"marks":1547,"data":1548}," (4.9M accounts), ",[],{},{"nodeType":456,"data":1550,"content":1552},{"uri":1551},"https://www.theregister.com/2026/04/24/shinyhunters_claim_cruise_giant_carnivals/",[1553],{"nodeType":437,"value":1554,"marks":1555,"data":1556},"Carnival Corporation",[],{},{"nodeType":437,"value":1558,"marks":1559,"data":1560}," (6M records), and",[],{},{"nodeType":456,"data":1562,"content":1564},{"uri":1563},"https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/",[1565],{"nodeType":437,"value":1566,"marks":1567,"data":1568}," Pitney Bowes",[],{},{"nodeType":437,"value":1570,"marks":1571,"data":1572}," (8.2M emails per HIBP). ",[],{},{"nodeType":456,"data":1574,"content":1576},{"uri":1575},"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/",[1577],{"nodeType":437,"value":1578,"marks":1579,"data":1580},"Optimizely",[],{},{"nodeType":437,"value":1582,"marks":1583,"data":1584}," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",[],{},{"nodeType":433,"data":1586,"content":1587},{},[1588,1592,1598,1602,1610,1614,1622],{"nodeType":437,"value":1589,"marks":1590,"data":1591},"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",[],{},{"nodeType":456,"data":1593,"content":1594},{"uri":477},[1595],{"nodeType":437,"value":480,"marks":1596,"data":1597},[],{},{"nodeType":437,"value":1599,"marks":1600,"data":1601}," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",[],{},{"nodeType":456,"data":1603,"content":1605},{"uri":1604},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[1606],{"nodeType":437,"value":1607,"marks":1608,"data":1609},"Salesloft, Drift, and GainSight",[],{},{"nodeType":437,"value":1611,"marks":1612,"data":1613}," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",[],{},{"nodeType":456,"data":1615,"content":1617},{"uri":1616},"https://pushsecurity.com/blog/unpacking-the-vercel-breach",[1618],{"nodeType":437,"value":1619,"marks":1620,"data":1621},"repeated at scale",[],{},{"nodeType":437,"value":1623,"marks":1624,"data":1625},".",[],{},{"nodeType":590,"data":1627,"content":1628},{},[1629],{"nodeType":437,"value":1630,"marks":1631,"data":1633},"Copycats and nation-state adoption",[1632],{"type":510},{},{"nodeType":433,"data":1635,"content":1636},{},[1637,1641,1649,1653,1661,1665,1673,1677,1685],{"nodeType":437,"value":1638,"marks":1639,"data":1640},"Wider groups are now running the SLH playbook independently. ",[],{},{"nodeType":456,"data":1642,"content":1644},{"uri":1643},"https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/",[1645],{"nodeType":437,"value":1646,"marks":1647,"data":1648},"Pink",[],{},{"nodeType":437,"value":1650,"marks":1651,"data":1652}," (the latest rebrand in the",[],{},{"nodeType":456,"data":1654,"content":1656},{"uri":1655},"https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments",[1657],{"nodeType":437,"value":1658,"marks":1659,"data":1660}," BlackFile",[],{},{"nodeType":437,"value":1662,"marks":1663,"data":1664},"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",[],{},{"nodeType":456,"data":1666,"content":1668},{"uri":1667},"https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/",[1669],{"nodeType":437,"value":1670,"marks":1671,"data":1672},"Helix",[],{},{"nodeType":437,"value":1674,"marks":1675,"data":1676}," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",[],{},{"nodeType":456,"data":1678,"content":1680},{"uri":1679},"https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/",[1681],{"nodeType":437,"value":1682,"marks":1683,"data":1684},"KongTuke",[],{},{"nodeType":437,"value":1686,"marks":1687,"data":1688},", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",[],{},{"nodeType":433,"data":1690,"content":1691},{},[1692,1696,1704,1708,1716],{"nodeType":437,"value":1693,"marks":1694,"data":1695},"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",[],{},{"nodeType":456,"data":1697,"content":1699},{"uri":1698},"https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",[1700],{"nodeType":437,"value":1701,"marks":1702,"data":1703},"compromised hotel and conference Wi-Fi gateways",[],{},{"nodeType":437,"value":1705,"marks":1706,"data":1707}," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",[],{},{"nodeType":456,"data":1709,"content":1711},{"uri":1710},"https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/",[1712],{"nodeType":437,"value":1713,"marks":1714,"data":1715},"Google Threat Intelligence mapped",[],{},{"nodeType":437,"value":1717,"marks":1718,"data":1719}," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",[],{},{"nodeType":548,"data":1721,"content":1725},{"target":1722},{"sys":1723},{"id":1724,"type":553,"linkType":554},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"nodeType":557,"data":1727,"content":1728},{},[],{"nodeType":561,"data":1730,"content":1731},{},[1732],{"nodeType":437,"value":1733,"marks":1734,"data":1736},"Phishing infrastructure has reached an industrial scale",[1735],{"type":510},{},{"nodeType":433,"data":1738,"content":1739},{},[1740],{"nodeType":437,"value":1741,"marks":1742,"data":1743},"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",[],{},{"nodeType":590,"data":1745,"content":1746},{},[1747],{"nodeType":437,"value":1748,"marks":1749,"data":1751},"Device code phishing goes mainstream",[1750],{"type":510},{},{"nodeType":433,"data":1753,"content":1754},{},[1755,1759,1765],{"nodeType":437,"value":1756,"marks":1757,"data":1758},"We're tracking a huge spike in ",[],{},{"nodeType":456,"data":1760,"content":1761},{"uri":477},[1762],{"nodeType":437,"value":480,"marks":1763,"data":1764},[],{},{"nodeType":437,"value":1766,"marks":1767,"data":1768}," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",[],{},{"nodeType":433,"data":1770,"content":1771},{},[1772,1776,1784,1788,1796,1800,1808,1812,1820],{"nodeType":437,"value":1773,"marks":1774,"data":1775},"What began with ",[],{},{"nodeType":456,"data":1777,"content":1779},{"uri":1778},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[1780],{"nodeType":437,"value":1781,"marks":1782,"data":1783},"Storm-2372's nation-state campaigns",[],{},{"nodeType":437,"value":1785,"marks":1786,"data":1787}," in August 2024 has proliferated through criminal kits like ",[],{},{"nodeType":456,"data":1789,"content":1791},{"uri":1790},"https://thehackernews.com/2026/05/the-new-phishing-click-how-oauth-consent.html",[1792],{"nodeType":437,"value":1793,"marks":1794,"data":1795},"EvilTokens",[],{},{"nodeType":437,"value":1797,"marks":1798,"data":1799}," (340+ organizations in its first five weeks), ",[],{},{"nodeType":456,"data":1801,"content":1803},{"uri":1802},"https://www.huntress.com/blog/kali365-device-code-phishing-kit",[1804],{"nodeType":437,"value":1805,"marks":1806,"data":1807},"Kali365",[],{},{"nodeType":437,"value":1809,"marks":1810,"data":1811}," (which earned an FBI public advisory), ",[],{},{"nodeType":456,"data":1813,"content":1815},{"uri":1814},"https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/",[1816],{"nodeType":437,"value":1817,"marks":1818,"data":1819},"ARToken",[],{},{"nodeType":437,"value":1821,"marks":1822,"data":1823},", DEBULL, Forg365, and many more.",[],{},{"nodeType":548,"data":1825,"content":1829},{"target":1826},{"sys":1827},{"id":1828,"type":553,"linkType":554},"7G6ytXRQPWatOyYarqgMK2",[],{"nodeType":433,"data":1831,"content":1832},{},[1833],{"nodeType":437,"value":1834,"marks":1835,"data":1836},"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",[],{},{"nodeType":433,"data":1838,"content":1839},{},[1840,1844,1851],{"nodeType":437,"value":1841,"marks":1842,"data":1843},"Established AiTM vendors like Tycoon 2FA have ",[],{},{"nodeType":456,"data":1845,"content":1846},{"uri":657},[1847],{"nodeType":437,"value":1848,"marks":1849,"data":1850},"added device code phishing",[],{},{"nodeType":437,"value":1852,"marks":1853,"data":1854}," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",[],{},{"nodeType":548,"data":1856,"content":1860},{"target":1857},{"sys":1858},{"id":1859,"type":553,"linkType":554},"3urXbEwK0OSjXQ7lOMDEoc",[],{"nodeType":433,"data":1862,"content":1863},{},[1864],{"nodeType":437,"value":1865,"marks":1866,"data":1867},"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",[],{},{"nodeType":548,"data":1869,"content":1873},{"target":1870},{"sys":1871},{"id":1872,"type":553,"linkType":554},"4ipTS2U4HE1VLSLmA6DJgB",[],{"nodeType":433,"data":1875,"content":1876},{},[1877],{"nodeType":437,"value":1878,"marks":1879,"data":1880},"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",[],{},{"nodeType":548,"data":1882,"content":1886},{"target":1883},{"sys":1884},{"id":1885,"type":553,"linkType":554},"3UDzUCCizPJhXp3SsoZuSK",[],{"nodeType":433,"data":1888,"content":1889},{},[1890],{"nodeType":437,"value":1891,"marks":1892,"data":1893},"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",[],{},{"nodeType":548,"data":1895,"content":1899},{"target":1896},{"sys":1897},{"id":1898,"type":553,"linkType":554},"3SPsKzwBNxl4d9QRukBtwt",[],{"nodeType":590,"data":1901,"content":1902},{},[1903],{"nodeType":437,"value":1904,"marks":1905,"data":1907},"PhaaS platform evolution and evasion",[1906],{"type":510},{},{"nodeType":433,"data":1909,"content":1910},{},[1911,1915,1923,1927,1935,1939,1947],{"nodeType":437,"value":1912,"marks":1913,"data":1914},"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",[],{},{"nodeType":456,"data":1916,"content":1918},{"uri":1917},"https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas",[1919],{"nodeType":437,"value":1920,"marks":1921,"data":1922},"Bluekit",[],{},{"nodeType":437,"value":1924,"marks":1925,"data":1926},", ",[],{},{"nodeType":456,"data":1928,"content":1930},{"uri":1929},"https://abnormal.ai/blog/blacksite-aitm-phishing-kit-cloaked-gg",[1931],{"nodeType":437,"value":1932,"marks":1933,"data":1934},"Blacksite and Cloaked.gg",[],{},{"nodeType":437,"value":1936,"marks":1937,"data":1938}," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",[],{},{"nodeType":456,"data":1940,"content":1942},{"uri":1941},"https://threatactix.com/2026/07/02/a-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations/",[1943],{"nodeType":437,"value":1944,"marks":1945,"data":1946},"WackoGinx",[],{},{"nodeType":437,"value":1948,"marks":1949,"data":1950},", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",[],{},{"nodeType":433,"data":1952,"content":1953},{},[1954,1958,1966,1970,1978],{"nodeType":437,"value":1955,"marks":1956,"data":1957},"Sneaky 2FA changes have also been documented, with what ",[],{},{"nodeType":456,"data":1959,"content":1961},{"uri":1960},"https://zerobec.com/blog/sneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[1962],{"nodeType":437,"value":1963,"marks":1964,"data":1965},"ZeroBEC calls \"route polymorphism\"",[],{},{"nodeType":437,"value":1967,"marks":1968,"data":1969}," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",[],{},{"nodeType":456,"data":1971,"content":1973},{"uri":1972},"https://blog.barracuda.com/2026/06/29/email-threat-radar-june-2026",[1974],{"nodeType":437,"value":1975,"marks":1976,"data":1977},"split-click buttons and blob URLs",[],{},{"nodeType":437,"value":1979,"marks":1980,"data":1981}," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",[],{},{"nodeType":433,"data":1983,"content":1984},{},[1985,1989,1997],{"nodeType":437,"value":1986,"marks":1987,"data":1988},"The speed of technique adoption across these platforms is itself accelerating. ",[],{},{"nodeType":456,"data":1990,"content":1992},{"uri":1991},"https://sublime.security/blog/flowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation/",[1993],{"nodeType":437,"value":1994,"marks":1995,"data":1996},"FlowerStorm adopted",[],{},{"nodeType":437,"value":1998,"marks":1999,"data":2000}," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",[],{},{"nodeType":433,"data":2002,"content":2003},{},[2004,2008,2016,2020,2027],{"nodeType":437,"value":2005,"marks":2006,"data":2007},"At the same time, target surfaces are expanding: ",[],{},{"nodeType":456,"data":2009,"content":2011},{"uri":2010},"https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/",[2012],{"nodeType":437,"value":2013,"marks":2014,"data":2015},"Datadog documented",[],{},{"nodeType":437,"value":2017,"marks":2018,"data":2019}," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",[],{},{"nodeType":456,"data":2021,"content":2022},{"uri":458},[2023],{"nodeType":437,"value":2024,"marks":2025,"data":2026},"MFA downgrade",[],{},{"nodeType":437,"value":2028,"marks":2029,"data":2030}," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",[],{},{"nodeType":590,"data":2032,"content":2033},{},[2034],{"nodeType":437,"value":2035,"marks":2036,"data":2038},"ClickFix as a service",[2037],{"type":510},{},{"nodeType":433,"data":2040,"content":2041},{},[2042,2046,2054,2058,2066],{"nodeType":437,"value":2043,"marks":2044,"data":2045},"ClickFix has also continued to industrialize. ",[],{},{"nodeType":456,"data":2047,"content":2049},{"uri":2048},"https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/",[2050],{"nodeType":437,"value":2051,"marks":2052,"data":2053},"Sekoia documented",[],{},{"nodeType":437,"value":2055,"marks":2056,"data":2057}," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",[],{},{"nodeType":456,"data":2059,"content":2061},{"uri":2060},"https://kqlquery.com/posts/clickfix-gift-that-keeps-on-giving/",[2062],{"nodeType":437,"value":2063,"marks":2064,"data":2065},"mapped approximately 3,000 live ClickFix payloads",[],{},{"nodeType":437,"value":2067,"marks":2068,"data":2069}," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",[],{},{"nodeType":433,"data":2071,"content":2072},{},[2073,2077,2085,2089,2097],{"nodeType":437,"value":2074,"marks":2075,"data":2076},"The technique has also expanded cross-platform, with Unit 42 documenting ",[],{},{"nodeType":456,"data":2078,"content":2080},{"uri":2079},"https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/",[2081],{"nodeType":437,"value":2082,"marks":2083,"data":2084},"macOS ClickFix variants",[],{},{"nodeType":437,"value":2086,"marks":2087,"data":2088}," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",[],{},{"nodeType":456,"data":2090,"content":2092},{"uri":2091},"https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/",[2093],{"nodeType":437,"value":2094,"marks":2095,"data":2096},"700 Ghost CMS sites were compromised",[],{},{"nodeType":437,"value":2098,"marks":2099,"data":2100}," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",[],{},{"nodeType":433,"data":2102,"content":2103},{},[2104,2108,2116,2120,2128],{"nodeType":437,"value":2105,"marks":2106,"data":2107},"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",[],{},{"nodeType":456,"data":2109,"content":2111},{"uri":2110},"https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html",[2112],{"nodeType":437,"value":2113,"marks":2114,"data":2115},"BlueNoroff",[],{},{"nodeType":437,"value":2117,"marks":2118,"data":2119}," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",[],{},{"nodeType":456,"data":2121,"content":2123},{"uri":2122},"https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/",[2124],{"nodeType":437,"value":2125,"marks":2126,"data":2127},"Famous Chollima",[],{},{"nodeType":437,"value":2129,"marks":2130,"data":2131}," embedding ClickFix in multi-stage fake job interviews.",[],{},{"nodeType":590,"data":2133,"content":2134},{},[2135],{"nodeType":437,"value":2136,"marks":2137,"data":2139},"Vishing as a payload delivery mechanism",[2138],{"type":510},{},{"nodeType":433,"data":2141,"content":2142},{},[2143],{"nodeType":437,"value":2144,"marks":2145,"data":2146},"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",[],{},{"nodeType":433,"data":2148,"content":2149},{},[2150,2154,2162],{"nodeType":437,"value":2151,"marks":2152,"data":2153},"When Push researchers ",[],{},{"nodeType":456,"data":2155,"content":2157},{"uri":2156},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[2158],{"nodeType":437,"value":2159,"marks":2160,"data":2161},"infiltrated the phishing panels",[],{},{"nodeType":437,"value":2163,"marks":2164,"data":2165}," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",[],{},{"nodeType":433,"data":2167,"content":2168},{},[2169,2173,2181,2185,2193,2197,2205,2209,2217],{"nodeType":437,"value":2170,"marks":2171,"data":2172},"The financial scale is now quantifiable: ",[],{},{"nodeType":456,"data":2174,"content":2176},{"uri":2175},"https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks",[2177],{"nodeType":437,"value":2178,"marks":2179,"data":2180},"Luna Moth",[],{},{"nodeType":437,"value":2182,"marks":2183,"data":2184}," (Silent Ransom Group), a ",[],{},{"nodeType":456,"data":2186,"content":2188},{"uri":2187},"https://www.crowdstrike.com/en-us/adversaries/chatty-spider/",[2189],{"nodeType":437,"value":2190,"marks":2191,"data":2192},"Russia-linked Conti spinoff",[],{},{"nodeType":437,"value":2194,"marks":2195,"data":2196}," operating independently of the Com, has extracted ",[],{},{"nodeType":456,"data":2198,"content":2200},{"uri":2199},"https://www.theinsurer.com/ti/news/exclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27/",[2201],{"nodeType":437,"value":2202,"marks":2203,"data":2204},"up to $48 million",[],{},{"nodeType":437,"value":2206,"marks":2207,"data":2208}," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",[],{},{"nodeType":456,"data":2210,"content":2212},{"uri":2211},"https://www.ic3.gov/CSA/2026/260526.pdf",[2213],{"nodeType":437,"value":2214,"marks":2215,"data":2216},"FBI issuing a dedicated flash alert",[],{},{"nodeType":437,"value":1623,"marks":2218,"data":2219},[],{},{"nodeType":433,"data":2221,"content":2222},{},[2223,2227,2235,2239,2247],{"nodeType":437,"value":2224,"marks":2225,"data":2226},"The infrastructure behind these campaigns is industrializing independently. ",[],{},{"nodeType":456,"data":2228,"content":2230},{"uri":2229},"https://www.okta.com/blog/threat-intelligence/behind-the-scenes-of-a-vishing-operation/",[2231],{"nodeType":437,"value":2232,"marks":2233,"data":2234},"Okta obtained access to Work Panel",[],{},{"nodeType":437,"value":2236,"marks":2237,"data":2238},", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",[],{},{"nodeType":456,"data":2240,"content":2242},{"uri":2241},"https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[2243],{"nodeType":437,"value":2244,"marks":2245,"data":2246},"documented a dedicated Teams-vishing initial access broker",[],{},{"nodeType":437,"value":2248,"marks":2249,"data":2250}," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",[],{},{"nodeType":590,"data":2252,"content":2253},{},[2254],{"nodeType":437,"value":2255,"marks":2256,"data":2258},"OAuth supply chain attacks",[2257],{"type":510},{},{"nodeType":433,"data":2260,"content":2261},{},[2262,2266,2273],{"nodeType":437,"value":2263,"marks":2264,"data":2265},"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",[],{},{"nodeType":456,"data":2267,"content":2268},{"uri":1604},[2269],{"nodeType":437,"value":2270,"marks":2271,"data":2272},"Salesloft/Drift supply chain attack",[],{},{"nodeType":437,"value":2274,"marks":2275,"data":2276}," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",[],{},{"nodeType":433,"data":2278,"content":2279},{},[2280,2284,2292,2296,2304,2308,2316],{"nodeType":437,"value":2281,"marks":2282,"data":2283},"In 2026, the ",[],{},{"nodeType":456,"data":2285,"content":2287},{"uri":2286},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[2288],{"nodeType":437,"value":2289,"marks":2290,"data":2291},"Anodot compromise",[],{},{"nodeType":437,"value":2293,"marks":2294,"data":2295}," cascaded through to Vimeo, Rockstar Games, and Zara. The ",[],{},{"nodeType":456,"data":2297,"content":2299},{"uri":2298},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[2300],{"nodeType":437,"value":2301,"marks":2302,"data":2303},"Context.ai → Vercel",[],{},{"nodeType":437,"value":2305,"marks":2306,"data":2307}," breach followed the same structural pattern. And the ",[],{},{"nodeType":456,"data":2309,"content":2311},{"uri":2310},"https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/",[2312],{"nodeType":437,"value":2313,"marks":2314,"data":2315},"Klue/Icarus breach",[],{},{"nodeType":437,"value":2317,"marks":2318,"data":2319}," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",[],{},{"nodeType":557,"data":2321,"content":2322},{},[],{"nodeType":561,"data":2324,"content":2325},{},[2326],{"nodeType":437,"value":2327,"marks":2328,"data":2330},"AI is a force multiplier for attackers",[2329],{"type":510},{},{"nodeType":433,"data":2332,"content":2333},{},[2334],{"nodeType":437,"value":2335,"marks":2336,"data":2337},"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",[],{},{"nodeType":433,"data":2339,"content":2340},{},[2341],{"nodeType":437,"value":2342,"marks":2343,"data":2344},"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",[],{},{"nodeType":433,"data":2346,"content":2347},{},[2348,2352,2360],{"nodeType":437,"value":2349,"marks":2350,"data":2351},"You can see more examples of these kits under the hood in our blog post ",[],{},{"nodeType":456,"data":2353,"content":2355},{"uri":2354},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[2356],{"nodeType":437,"value":2357,"marks":2358,"data":2359},"infiltrating a criminal phishing panel. ",[],{},{"nodeType":437,"value":21,"marks":2361,"data":2362},[],{},{"nodeType":548,"data":2364,"content":2368},{"target":2365},{"sys":2366},{"id":2367,"type":553,"linkType":554},"01mOiserRBXraawXwQyJNm",[],{"nodeType":433,"data":2370,"content":2371},{},[2372],{"nodeType":437,"value":2373,"marks":2374,"data":2375},"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",[],{},{"nodeType":2377,"data":2378,"content":2379},"unordered-list",{},[2380,2403,2424,2446,2468],{"nodeType":2381,"data":2382,"content":2383},"list-item",{},[2384],{"nodeType":433,"data":2385,"content":2386},{},[2387,2391,2399],{"nodeType":437,"value":2388,"marks":2389,"data":2390},"The first major device code phishing kit identified in the wild, EvilTokens, ",[],{},{"nodeType":456,"data":2392,"content":2394},{"uri":2393},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[2395],{"nodeType":437,"value":2396,"marks":2397,"data":2398},"heavily used Railway",[],{},{"nodeType":437,"value":2400,"marks":2401,"data":2402},", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",[],{},{"nodeType":2381,"data":2404,"content":2405},{},[2406],{"nodeType":433,"data":2407,"content":2408},{},[2409,2413,2420],{"nodeType":437,"value":2410,"marks":2411,"data":2412},"Kali365's E2 edition includes an AI-powered BEC module that ",[],{},{"nodeType":456,"data":2414,"content":2415},{"uri":1802},[2416],{"nodeType":437,"value":2417,"marks":2418,"data":2419},"uses Claude Sonnet",[],{},{"nodeType":437,"value":2421,"marks":2422,"data":2423}," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",[],{},{"nodeType":2381,"data":2425,"content":2426},{},[2427],{"nodeType":433,"data":2428,"content":2429},{},[2430,2433,2442],{"nodeType":437,"value":21,"marks":2431,"data":2432},[],{},{"nodeType":456,"data":2434,"content":2436},{"uri":2435},"https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html",[2437],{"nodeType":437,"value":2438,"marks":2439,"data":2441},"Rapid7's analysis of an exposed server",[2440],{"type":483},{},{"nodeType":437,"value":2443,"marks":2444,"data":2445}," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",[],{},{"nodeType":2381,"data":2447,"content":2448},{},[2449],{"nodeType":433,"data":2450,"content":2451},{},[2452,2456,2464],{"nodeType":437,"value":2453,"marks":2454,"data":2455},"Three independent operators were ",[],{},{"nodeType":456,"data":2457,"content":2459},{"uri":2458},"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html",[2460],{"nodeType":437,"value":2461,"marks":2462,"data":2463},"found running kits from public GitHub forks",[],{},{"nodeType":437,"value":2465,"marks":2466,"data":2467}," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",[],{},{"nodeType":2381,"data":2469,"content":2470},{},[2471],{"nodeType":433,"data":2472,"content":2473},{},[2474,2478,2486],{"nodeType":437,"value":2475,"marks":2476,"data":2477},"The tooling itself is starting to embed AI as a product feature — ",[],{},{"nodeType":456,"data":2479,"content":2481},{"uri":2480},"https://www.varonis.com/blog/dolphin-x-stealer",[2482],{"nodeType":437,"value":2483,"marks":2484,"data":2485},"Dolphin X",[],{},{"nodeType":437,"value":2487,"marks":2488,"data":2489},", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",[],{},{"nodeType":433,"data":2491,"content":2492},{},[2493,2497,2505,2509,2517,2521,2529],{"nodeType":437,"value":2494,"marks":2495,"data":2496},"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",[],{},{"nodeType":456,"data":2498,"content":2500},{"uri":2499},"https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[2501],{"nodeType":437,"value":2502,"marks":2503,"data":2504},"malicious Claude.ai Artifact impersonating a download portal",[],{},{"nodeType":437,"value":2506,"marks":2507,"data":2508}," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",[],{},{"nodeType":456,"data":2510,"content":2512},{"uri":2511},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[2513],{"nodeType":437,"value":2514,"marks":2515,"data":2516},"LLMShare attack pattern",[],{},{"nodeType":437,"value":2518,"marks":2519,"data":2520}," we documented in May. A second campaign, ",[],{},{"nodeType":456,"data":2522,"content":2524},{"uri":2523},"https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering",[2525],{"nodeType":437,"value":2526,"marks":2527,"data":2528},"MacSync",[],{},{"nodeType":437,"value":2530,"marks":2531,"data":2532},", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",[],{},{"nodeType":590,"data":2534,"content":2535},{},[2536],{"nodeType":437,"value":2537,"marks":2538,"data":2540},"But the core techniques aren't changing",[2539],{"type":510},{},{"nodeType":433,"data":2542,"content":2543},{},[2544,2548,2556],{"nodeType":437,"value":2545,"marks":2546,"data":2547},"AI compresses the bottom layers of the ",[],{},{"nodeType":456,"data":2549,"content":2551},{"uri":2550},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era/",[2552],{"nodeType":437,"value":2553,"marks":2554,"data":2555},"Pyramid of Pain",[],{},{"nodeType":437,"value":2557,"marks":2558,"data":2559}," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",[],{},{"nodeType":433,"data":2561,"content":2562},{},[2563],{"nodeType":437,"value":2564,"marks":2565,"data":2566},"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",[],{},{"nodeType":557,"data":2568,"content":2569},{},[],{"nodeType":561,"data":2571,"content":2572},{},[2573],{"nodeType":437,"value":2574,"marks":2575,"data":2577},"What this means for defenders",[2576],{"type":510},{},{"nodeType":433,"data":2579,"content":2580},{},[2581],{"nodeType":437,"value":2582,"marks":2583,"data":2584},"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",[],{},{"nodeType":2377,"data":2586,"content":2587},{},[2588,2598,2608,2618],{"nodeType":2381,"data":2589,"content":2590},{},[2591],{"nodeType":433,"data":2592,"content":2593},{},[2594],{"nodeType":437,"value":2595,"marks":2596,"data":2597},"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",[],{},{"nodeType":2381,"data":2599,"content":2600},{},[2601],{"nodeType":433,"data":2602,"content":2603},{},[2604],{"nodeType":437,"value":2605,"marks":2606,"data":2607},"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",[],{},{"nodeType":2381,"data":2609,"content":2610},{},[2611],{"nodeType":433,"data":2612,"content":2613},{},[2614],{"nodeType":437,"value":2615,"marks":2616,"data":2617},"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",[],{},{"nodeType":2381,"data":2619,"content":2620},{},[2621],{"nodeType":433,"data":2622,"content":2623},{},[2624],{"nodeType":437,"value":2625,"marks":2626,"data":2627},"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",[],{},{"nodeType":433,"data":2629,"content":2630},{},[2631],{"nodeType":437,"value":2632,"marks":2633,"data":2634},"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",[],{},{"nodeType":557,"data":2636,"content":2637},{},[],{"nodeType":433,"data":2639,"content":2640},{},[2641],{"nodeType":437,"value":2642,"marks":2643,"data":2644},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":433,"data":2646,"content":2647},{},[2648],{"nodeType":437,"value":2649,"marks":2650,"data":2651},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":433,"data":2653,"content":2654},{},[2655,2658,2667],{"nodeType":437,"value":21,"marks":2656,"data":2657},[],{},{"nodeType":456,"data":2659,"content":2661},{"uri":2660},"https://pushsecurity.com/demo/",[2662],{"nodeType":437,"value":2663,"marks":2664,"data":2666},"Book a live demo to learn more.",[2665],{"type":483},{},{"nodeType":437,"value":21,"marks":2668,"data":2669},[],{},"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":2675},[2676,2680],{"sys":2677,"name":2679},{"id":2678},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2681,"name":2683},{"id":2682},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2685},[2686],{"fullName":2687,"firstName":2688,"jobTitle":2689,"profilePicture":2690},"Dan Green","Dan","Threat Research",{"url":2691},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1370,"sys":2693,"content":2695,"title":5698,"synopsis":5699,"hashTags":59,"publishedDate":5700,"slug":5701,"tagsCollection":5702,"authorsCollection":5708},{"id":2694},"5DmCqTU2Tg4adYScA5vT2x",{"json":2696},{"data":2697,"content":2698,"nodeType":429},{},[2699,2705,2725,2743,2750,2756,2763,2770,2773,2781,2787,2872,2891,2897,2904,3020,3026,3029,3037,3044,3050,3053,3061,3102,3108,3115,3122,3129,3136,3156,3162,3168,3174,3180,3186,3192,3198,3204,3471,3474,3482,3617,3623,3626,3634,3673,3807,3813,3816,3824,3971,3977,3980,3988,3994,4135,4141,4147,4150,4158,4305,4311,4314,4322,4468,4474,4477,4485,4580,4586,4589,4597,4691,4697,4700,4708,4714,4847,4853,4856,4864,4913,4919,4922,4930,5069,5074,5077,5085,5217,5223,5226,5234,5246,5253,5259,5265,5272,5293,5309,5315,5318,5326,5334,5355,5376,5381,5388,5395,5403,5410,5417,5424,5432,5439,5490,5496,5499,5507,5514,5521,5568,5574,5581,5584,5592,5599,5606,5626,5632,5639,5647,5654],{"data":2700,"content":2704,"nodeType":548},{"target":2701},{"sys":2702},{"id":2703,"type":553,"linkType":554},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":2706,"content":2707,"nodeType":433},{},[2708,2712,2721],{"data":2709,"marks":2710,"value":2711,"nodeType":437},{},[],"The OAuth 2.0 ",{"data":2713,"content":2715,"nodeType":456},{"uri":2714},"https://www.rfc-editor.org/rfc/rfc8628",[2716],{"data":2717,"marks":2718,"value":2720,"nodeType":437},{},[2719],{"type":483},"device authorization grant",{"data":2722,"marks":2723,"value":2724,"nodeType":437},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":2726,"content":2727,"nodeType":433},{},[2728,2731,2739],{"data":2729,"marks":2730,"value":21,"nodeType":437},{},[],{"data":2732,"content":2734,"nodeType":456},{"uri":2733},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[2735],{"data":2736,"marks":2737,"value":647,"nodeType":437},{},[2738],{"type":483},{"data":2740,"marks":2741,"value":2742,"nodeType":437},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":2744,"content":2745,"nodeType":433},{},[2746],{"data":2747,"marks":2748,"value":2749,"nodeType":437},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":2751,"content":2755,"nodeType":548},{"target":2752},{"sys":2753},{"id":2754,"type":553,"linkType":554},"Al0pGH8vmOYiufDFiAbt0",[],{"data":2757,"content":2758,"nodeType":433},{},[2759],{"data":2760,"marks":2761,"value":2762,"nodeType":437},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":2764,"content":2765,"nodeType":433},{},[2766],{"data":2767,"marks":2768,"value":2769,"nodeType":437},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":2771,"content":2772,"nodeType":557},{},[],{"data":2774,"content":2775,"nodeType":561},{},[2776],{"data":2777,"marks":2778,"value":2780,"nodeType":437},{},[2779],{"type":510},"A brief history of device code phishing",{"data":2782,"content":2786,"nodeType":548},{"target":2783},{"sys":2784},{"id":2785,"type":553,"linkType":554},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":2788,"content":2789,"nodeType":433},{},[2790,2794,2803,2807,2816,2820,2829,2833,2842,2846,2855,2859,2868],{"data":2791,"marks":2792,"value":2793,"nodeType":437},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":2795,"content":2797,"nodeType":456},{"uri":2796},"https://github.com/secureworks/PhishInSuits",[2798],{"data":2799,"marks":2800,"value":2802,"nodeType":437},{},[2801],{"type":483},"PhishInSuits",{"data":2804,"marks":2805,"value":2806,"nodeType":437},{},[]," a year later. A host of research followed, including ",{"data":2808,"content":2810,"nodeType":456},{"uri":2809},"https://github.com/secureworks/squarephish",[2811],{"data":2812,"marks":2813,"value":2815,"nodeType":437},{},[2814],{"type":483},"SquarePhish",{"data":2817,"marks":2818,"value":2819,"nodeType":437},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":2821,"content":2823,"nodeType":456},{"uri":2822},"https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/",[2824],{"data":2825,"marks":2826,"value":2828,"nodeType":437},{},[2827],{"type":483},"key research",{"data":2830,"marks":2831,"value":2832,"nodeType":437},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":2834,"content":2836,"nodeType":456},{"uri":2835},"https://github.com/denniskniep/DeviceCodePhishing",[2837],{"data":2838,"marks":2839,"value":2841,"nodeType":437},{},[2840],{"type":483},"DeviceCodePhishing tool",{"data":2843,"marks":2844,"value":2845,"nodeType":437},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":2847,"content":2849,"nodeType":456},{"uri":2848},"https://github.com/nromsdahl/squarephish2",[2850],{"data":2851,"marks":2852,"value":2854,"nodeType":437},{},[2853],{"type":483},"SquarePhish2",{"data":2856,"marks":2857,"value":2858,"nodeType":437},{},[]," and ",{"data":2860,"content":2862,"nodeType":456},{"uri":2861},"https://github.com/praetorian-inc/GitPhish",[2863],{"data":2864,"marks":2865,"value":2867,"nodeType":437},{},[2866],{"type":483},"GitPhish",{"data":2869,"marks":2870,"value":2871,"nodeType":437},{},[],", so shout out to those too). ",{"data":2873,"content":2874,"nodeType":433},{},[2875,2879,2887],{"data":2876,"marks":2877,"value":2878,"nodeType":437},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":2880,"content":2882,"nodeType":456},{"uri":2881},"https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html",[2883],{"data":2884,"marks":2885,"value":1793,"nodeType":437},{},[2886],{"type":483},{"data":2888,"marks":2889,"value":2890,"nodeType":437},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":2892,"content":2896,"nodeType":548},{"target":2893},{"sys":2894},{"id":2895,"type":553,"linkType":554},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":2898,"content":2899,"nodeType":433},{},[2900],{"data":2901,"marks":2902,"value":2903,"nodeType":437},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":2905,"content":2906,"nodeType":2377},{},[2907,2939,2960],{"data":2908,"content":2909,"nodeType":2381},{},[2910],{"data":2911,"content":2912,"nodeType":433},{},[2913,2917,2924,2927,2935],{"data":2914,"marks":2915,"value":2916,"nodeType":437},{},[],"Storm-2372, tracked by ",{"data":2918,"content":2919,"nodeType":456},{"uri":1778},[2920],{"data":2921,"marks":2922,"value":2923,"nodeType":437},{},[],"Microsoft",{"data":2925,"marks":2926,"value":2858,"nodeType":437},{},[],{"data":2928,"content":2930,"nodeType":456},{"uri":2929},"https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",[2931],{"data":2932,"marks":2933,"value":2934,"nodeType":437},{},[],"Volexity",{"data":2936,"marks":2937,"value":2938,"nodeType":437},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":2940,"content":2941,"nodeType":2381},{},[2942],{"data":2943,"content":2944,"nodeType":433},{},[2945,2949,2956],{"data":2946,"marks":2947,"value":2948,"nodeType":437},{},[],"The massive Salesforce campaign operated by ",{"data":2950,"content":2952,"nodeType":456},{"uri":2951},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[2953],{"data":2954,"marks":2955,"value":1407,"nodeType":437},{},[],{"data":2957,"marks":2958,"value":2959,"nodeType":437},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":2961,"content":2962,"nodeType":2381},{},[2963],{"data":2964,"content":2965,"nodeType":433},{},[2966,2970,2978,2982,2991,2995,3004,3008,3016],{"data":2967,"marks":2968,"value":2969,"nodeType":437},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":2971,"content":2973,"nodeType":456},{"uri":2972},"https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover",[2974],{"data":2975,"marks":2976,"value":2977,"nodeType":437},{},[],"multiple threat clusters",{"data":2979,"marks":2980,"value":2981,"nodeType":437},{},[]," tracked using device code phishing techniques, more ",{"data":2983,"content":2985,"nodeType":456},{"uri":2984},"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/",[2986],{"data":2987,"marks":2988,"value":2990,"nodeType":437},{},[2989],{"type":483},"criminal operations linked to SLH",{"data":2992,"marks":2993,"value":2994,"nodeType":437},{},[],", and ",{"data":2996,"content":2998,"nodeType":456},{"uri":2997},"https://newtonpaul.com/blog/device-code-phish-update/",[2999],{"data":3000,"marks":3001,"value":3003,"nodeType":437},{},[3002],{"type":483},"hundreds of organizations being targeted via PhaaS architecture,",{"data":3005,"marks":3006,"value":3007,"nodeType":437},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":3009,"content":3010,"nodeType":456},{"uri":2393},[3011],{"data":3012,"marks":3013,"value":3015,"nodeType":437},{},[3014],{"type":483},"Huntress",{"data":3017,"marks":3018,"value":3019,"nodeType":437},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":3021,"content":3025,"nodeType":548},{"target":3022},{"sys":3023},{"id":3024,"type":553,"linkType":554},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":3027,"content":3028,"nodeType":557},{},[],{"data":3030,"content":3031,"nodeType":561},{},[3032],{"data":3033,"marks":3034,"value":3036,"nodeType":437},{},[3035],{"type":510},"What we’re seeing in the wild",{"data":3038,"content":3039,"nodeType":433},{},[3040],{"data":3041,"marks":3042,"value":3043,"nodeType":437},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":3045,"content":3049,"nodeType":548},{"target":3046},{"sys":3047},{"id":3048,"type":553,"linkType":554},"nJCbTw85GKXdqrlIkzZwi",[],{"data":3051,"content":3052,"nodeType":557},{},[],{"data":3054,"content":3055,"nodeType":590},{},[3056],{"data":3057,"marks":3058,"value":3060,"nodeType":437},{},[3059],{"type":510},"“ANTIBOT” (EvilTokens)",{"data":3062,"content":3063,"nodeType":433},{},[3064,3067,3074,3077,3086,3090,3098],{"data":3065,"marks":3066,"value":21,"nodeType":437},{},[],{"data":3068,"content":3069,"nodeType":456},{"uri":2393},[3070],{"data":3071,"marks":3072,"value":3015,"nodeType":437},{},[3073],{"type":483},{"data":3075,"marks":3076,"value":1924,"nodeType":437},{},[],{"data":3078,"content":3080,"nodeType":456},{"uri":3079},"https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/",[3081],{"data":3082,"marks":3083,"value":3085,"nodeType":437},{},[3084],{"type":483},"Sekoia",{"data":3087,"marks":3088,"value":3089,"nodeType":437},{},[],", and researcher ",{"data":3091,"content":3092,"nodeType":456},{"uri":2997},[3093],{"data":3094,"marks":3095,"value":3097,"nodeType":437},{},[3096],{"type":483},"Paul Newton",{"data":3099,"marks":3100,"value":3101,"nodeType":437},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":3103,"content":3107,"nodeType":548},{"target":3104},{"sys":3105},{"id":3106,"type":553,"linkType":554},"1XNviq5OvMf5TEAc59F6g5",[],{"data":3109,"content":3110,"nodeType":433},{},[3111],{"data":3112,"marks":3113,"value":3114,"nodeType":437},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":3116,"content":3117,"nodeType":433},{},[3118],{"data":3119,"marks":3120,"value":3121,"nodeType":437},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a /generate-codes API call. ",{"data":3123,"content":3124,"nodeType":433},{},[3125],{"data":3126,"marks":3127,"value":3128,"nodeType":437},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":3130,"content":3131,"nodeType":433},{},[3132],{"data":3133,"marks":3134,"value":3135,"nodeType":437},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":3137,"content":3138,"nodeType":433},{},[3139,3143,3152],{"data":3140,"marks":3141,"value":3142,"nodeType":437},{},[],"The production version of EvilTokens showcases common ",{"data":3144,"content":3146,"nodeType":456},{"uri":3145},"https://phishing-techniques.pushsecurity.com/",[3147],{"data":3148,"marks":3149,"value":3151,"nodeType":437},{},[3150],{"type":483},"detection evasion techniques",{"data":3153,"marks":3154,"value":3155,"nodeType":437},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":3157,"content":3161,"nodeType":548},{"target":3158},{"sys":3159},{"id":3160,"type":553,"linkType":554},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":3163,"content":3167,"nodeType":548},{"target":3164},{"sys":3165},{"id":3166,"type":553,"linkType":554},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":3169,"content":3173,"nodeType":548},{"target":3170},{"sys":3171},{"id":3172,"type":553,"linkType":554},"3dbePPxVb4h4SauGg3glIL",[],{"data":3175,"content":3179,"nodeType":548},{"target":3176},{"sys":3177},{"id":3178,"type":553,"linkType":554},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":3181,"content":3185,"nodeType":548},{"target":3182},{"sys":3183},{"id":3184,"type":553,"linkType":554},"55XRqLSwUUi2D4ZVpJboml",[],{"data":3187,"content":3191,"nodeType":548},{"target":3188},{"sys":3189},{"id":3190,"type":553,"linkType":554},"5wg5yr2Lo8t3f72ZV815c",[],{"data":3193,"content":3197,"nodeType":548},{"target":3194},{"sys":3195},{"id":3196,"type":553,"linkType":554},"35cowlL6i3rkGXOGmSxlI1",[],{"data":3199,"content":3200,"nodeType":433},{},[3201],{"data":3202,"marks":3203,"value":21,"nodeType":437},{},[],{"data":3205,"content":3206,"nodeType":3470},{},[3207,3233,3317,3369,3393],{"data":3208,"content":3209,"nodeType":3232},{},[3210,3222],{"data":3211,"content":3212,"nodeType":3221},{},[3213],{"data":3214,"content":3215,"nodeType":433},{},[3216],{"data":3217,"marks":3218,"value":3220,"nodeType":437},{},[3219],{"type":510},"Frontend infrastructure","table-cell",{"data":3223,"content":3224,"nodeType":3221},{},[3225],{"data":3226,"content":3227,"nodeType":433},{},[3228],{"data":3229,"marks":3230,"value":3231,"nodeType":437},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev","table-row",{"data":3234,"content":3235,"nodeType":3232},{},[3236,3247],{"data":3237,"content":3238,"nodeType":3221},{},[3239],{"data":3240,"content":3241,"nodeType":433},{},[3242],{"data":3243,"marks":3244,"value":3246,"nodeType":437},{},[3245],{"type":510},"Backend infrastructure",{"data":3248,"content":3249,"nodeType":3221},{},[3250,3280],{"data":3251,"content":3252,"nodeType":433},{},[3253,3258,3262,3267,3271,3276],{"data":3254,"marks":3255,"value":3257,"nodeType":437},{},[3256],{"type":510},"Example IP: (V3) ",{"data":3259,"marks":3260,"value":3261,"nodeType":437},{},[],"162.220.232.71 (Railway AS400940) ",{"data":3263,"marks":3264,"value":3266,"nodeType":437},{},[3265],{"type":510},"(V2)",{"data":3268,"marks":3269,"value":3270,"nodeType":437},{},[]," 71.11.42.193 ",{"data":3272,"marks":3273,"value":3275,"nodeType":437},{},[3274],{"type":510},"(V1) ",{"data":3277,"marks":3278,"value":3279,"nodeType":437},{},[],"72.218.25.107",{"data":3281,"content":3282,"nodeType":433},{},[3283,3288,3292,3297,3301,3305,3309,3313],{"data":3284,"marks":3285,"value":3287,"nodeType":437},{},[3286],{"type":510},"Backend User Agent:",{"data":3289,"marks":3290,"value":3291,"nodeType":437},{},[]," ",{"data":3293,"marks":3294,"value":3296,"nodeType":437},{},[3295],{"type":510},"(V3) ",{"data":3298,"marks":3299,"value":3300,"nodeType":437},{},[],"node, ",{"data":3302,"marks":3303,"value":3266,"nodeType":437},{},[3304],{"type":510},{"data":3306,"marks":3307,"value":3308,"nodeType":437},{},[],", Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91 ",{"data":3310,"marks":3311,"value":3275,"nodeType":437},{},[3312],{"type":510},{"data":3314,"marks":3315,"value":3316,"nodeType":437},{},[],"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 OPR/56.0.3051.52 ",{"data":3318,"content":3319,"nodeType":3232},{},[3320,3331],{"data":3321,"content":3322,"nodeType":3221},{},[3323],{"data":3324,"content":3325,"nodeType":433},{},[3326],{"data":3327,"marks":3328,"value":3330,"nodeType":437},{},[3329],{"type":510},"Network paths",{"data":3332,"content":3333,"nodeType":3221},{},[3334,3341,3348,3355,3362],{"data":3335,"content":3336,"nodeType":433},{},[3337],{"data":3338,"marks":3339,"value":3340,"nodeType":437},{},[],"/api/rate-limit ",{"data":3342,"content":3343,"nodeType":433},{},[3344],{"data":3345,"marks":3346,"value":3347,"nodeType":437},{},[],"/api/fingerprint ",{"data":3349,"content":3350,"nodeType":433},{},[3351],{"data":3352,"marks":3353,"value":3354,"nodeType":437},{},[],"/api/captcha-verify ",{"data":3356,"content":3357,"nodeType":433},{},[3358],{"data":3359,"marks":3360,"value":3361,"nodeType":437},{},[],"/api/init /api/generate-code ",{"data":3363,"content":3364,"nodeType":433},{},[3365],{"data":3366,"marks":3367,"value":3368,"nodeType":437},{},[],"/api/check-auth",{"data":3370,"content":3371,"nodeType":3232},{},[3372,3383],{"data":3373,"content":3374,"nodeType":3221},{},[3375],{"data":3376,"content":3377,"nodeType":433},{},[3378],{"data":3379,"marks":3380,"value":3382,"nodeType":437},{},[3381],{"type":510},"Lure themes",{"data":3384,"content":3385,"nodeType":3221},{},[3386],{"data":3387,"content":3388,"nodeType":433},{},[3389],{"data":3390,"marks":3391,"value":3392,"nodeType":437},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":3394,"content":3395,"nodeType":3232},{},[3396,3407],{"data":3397,"content":3398,"nodeType":3221},{},[3399],{"data":3400,"content":3401,"nodeType":433},{},[3402],{"data":3403,"marks":3404,"value":3406,"nodeType":437},{},[3405],{"type":510},"Example Domain",{"data":3408,"content":3409,"nodeType":3221},{},[3410,3422,3434,3446,3458],{"data":3411,"content":3412,"nodeType":433},{},[3413,3418],{"data":3414,"marks":3415,"value":3417,"nodeType":437},{},[3416],{"type":510},"Precursor A:",{"data":3419,"marks":3420,"value":3421,"nodeType":437},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":3423,"content":3424,"nodeType":433},{},[3425,3430],{"data":3426,"marks":3427,"value":3429,"nodeType":437},{},[3428],{"type":510},"Precursor B: ",{"data":3431,"marks":3432,"value":3433,"nodeType":437},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":3435,"content":3436,"nodeType":433},{},[3437,3442],{"data":3438,"marks":3439,"value":3441,"nodeType":437},{},[3440],{"type":510},"Courts Access: ",{"data":3443,"marks":3444,"value":3445,"nodeType":437},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":3447,"content":3448,"nodeType":433},{},[3449,3454],{"data":3450,"marks":3451,"value":3453,"nodeType":437},{},[3452],{"type":510},"Early ANTIBOT:",{"data":3455,"marks":3456,"value":3457,"nodeType":437},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":3459,"content":3460,"nodeType":433},{},[3461,3466],{"data":3462,"marks":3463,"value":3465,"nodeType":437},{},[3464],{"type":510},"Production ANTIBOT: ",{"data":3467,"marks":3468,"value":3469,"nodeType":437},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev","table",{"data":3472,"content":3473,"nodeType":557},{},[],{"data":3475,"content":3476,"nodeType":590},{},[3477],{"data":3478,"marks":3479,"value":3481,"nodeType":437},{},[3480],{"type":510},"“SHAREFILE”",{"data":3483,"content":3484,"nodeType":3470},{},[3485,3508,3547,3570,3593],{"data":3486,"content":3487,"nodeType":3232},{},[3488,3498],{"data":3489,"content":3490,"nodeType":3221},{},[3491],{"data":3492,"content":3493,"nodeType":433},{},[3494],{"data":3495,"marks":3496,"value":3220,"nodeType":437},{},[3497],{"type":510},{"data":3499,"content":3500,"nodeType":3221},{},[3501],{"data":3502,"content":3503,"nodeType":433},{},[3504],{"data":3505,"marks":3506,"value":3507,"nodeType":437},{},[],"No hosting markers visible.",{"data":3509,"content":3510,"nodeType":3232},{},[3511,3521],{"data":3512,"content":3513,"nodeType":3221},{},[3514],{"data":3515,"content":3516,"nodeType":433},{},[3517],{"data":3518,"marks":3519,"value":3246,"nodeType":437},{},[3520],{"type":510},{"data":3522,"content":3523,"nodeType":3221},{},[3524,3536],{"data":3525,"content":3526,"nodeType":433},{},[3527,3532],{"data":3528,"marks":3529,"value":3531,"nodeType":437},{},[3530],{"type":510},"Example IP:",{"data":3533,"marks":3534,"value":3535,"nodeType":437},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":3537,"content":3538,"nodeType":433},{},[3539,3543],{"data":3540,"marks":3541,"value":3287,"nodeType":437},{},[3542],{"type":510},{"data":3544,"marks":3545,"value":3546,"nodeType":437},{},[]," node",{"data":3548,"content":3549,"nodeType":3232},{},[3550,3560],{"data":3551,"content":3552,"nodeType":3221},{},[3553],{"data":3554,"content":3555,"nodeType":433},{},[3556],{"data":3557,"marks":3558,"value":3330,"nodeType":437},{},[3559],{"type":510},{"data":3561,"content":3562,"nodeType":3221},{},[3563],{"data":3564,"content":3565,"nodeType":433},{},[3566],{"data":3567,"marks":3568,"value":3569,"nodeType":437},{},[],"POST /api/device/start  POST /api/device/poll",{"data":3571,"content":3572,"nodeType":3232},{},[3573,3583],{"data":3574,"content":3575,"nodeType":3221},{},[3576],{"data":3577,"content":3578,"nodeType":433},{},[3579],{"data":3580,"marks":3581,"value":3382,"nodeType":437},{},[3582],{"type":510},{"data":3584,"content":3585,"nodeType":3221},{},[3586],{"data":3587,"content":3588,"nodeType":433},{},[3589],{"data":3590,"marks":3591,"value":3592,"nodeType":437},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download/preview buttons",{"data":3594,"content":3595,"nodeType":3232},{},[3596,3607],{"data":3597,"content":3598,"nodeType":3221},{},[3599],{"data":3600,"content":3601,"nodeType":433},{},[3602],{"data":3603,"marks":3604,"value":3606,"nodeType":437},{},[3605],{"type":510},"Example domain",{"data":3608,"content":3609,"nodeType":3221},{},[3610],{"data":3611,"content":3612,"nodeType":433},{},[3613],{"data":3614,"marks":3615,"value":3616,"nodeType":437},{},[],"cghdfg[.]vbchkioi[.]su",{"data":3618,"content":3622,"nodeType":548},{"target":3619},{"sys":3620},{"id":3621,"type":553,"linkType":554},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":3624,"content":3625,"nodeType":557},{},[],{"data":3627,"content":3628,"nodeType":590},{},[3629],{"data":3630,"marks":3631,"value":3633,"nodeType":437},{},[3632],{"type":510},"Kali365 (internal name “CLURE”)",{"data":3635,"content":3636,"nodeType":433},{},[3637,3641,3645,3649,3657,3661,3669],{"data":3638,"marks":3639,"value":3640,"nodeType":437},{},[],"Clure was recently linked to the ",{"data":3642,"marks":3643,"value":1805,"nodeType":437},{},[3644],{"type":510},{"data":3646,"marks":3647,"value":3648,"nodeType":437},{},[]," PhaaS platform based on an ",{"data":3650,"content":3652,"nodeType":456},{"uri":3651},"https://www.ic3.gov/PSA/2026/PSA260521",[3653],{"data":3654,"marks":3655,"value":3656,"nodeType":437},{},[],"FBI advisory",{"data":3658,"marks":3659,"value":3660,"nodeType":437},{},[]," and additional research from ",{"data":3662,"content":3664,"nodeType":456},{"uri":3663},"https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/",[3665],{"data":3666,"marks":3667,"value":3668,"nodeType":437},{},[],"Arctic Wolf",{"data":3670,"marks":3671,"value":3672,"nodeType":437},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":3674,"content":3675,"nodeType":3470},{},[3676,3699,3738,3761,3784],{"data":3677,"content":3678,"nodeType":3232},{},[3679,3689],{"data":3680,"content":3681,"nodeType":3221},{},[3682],{"data":3683,"content":3684,"nodeType":433},{},[3685],{"data":3686,"marks":3687,"value":3220,"nodeType":437},{},[3688],{"type":510},{"data":3690,"content":3691,"nodeType":3221},{},[3692],{"data":3693,"content":3694,"nodeType":433},{},[3695],{"data":3696,"marks":3697,"value":3698,"nodeType":437},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":3700,"content":3701,"nodeType":3232},{},[3702,3712],{"data":3703,"content":3704,"nodeType":3221},{},[3705],{"data":3706,"content":3707,"nodeType":433},{},[3708],{"data":3709,"marks":3710,"value":3246,"nodeType":437},{},[3711],{"type":510},{"data":3713,"content":3714,"nodeType":3221},{},[3715,3727],{"data":3716,"content":3717,"nodeType":433},{},[3718,3723],{"data":3719,"marks":3720,"value":3722,"nodeType":437},{},[3721],{"type":510},"Example IP: ",{"data":3724,"marks":3725,"value":3726,"nodeType":437},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":3728,"content":3729,"nodeType":433},{},[3730,3734],{"data":3731,"marks":3732,"value":3287,"nodeType":437},{},[3733],{"type":510},{"data":3735,"marks":3736,"value":3737,"nodeType":437},{},[]," python-requests/2.32.5",{"data":3739,"content":3740,"nodeType":3232},{},[3741,3751],{"data":3742,"content":3743,"nodeType":3221},{},[3744],{"data":3745,"content":3746,"nodeType":433},{},[3747],{"data":3748,"marks":3749,"value":3330,"nodeType":437},{},[3750],{"type":510},{"data":3752,"content":3753,"nodeType":3221},{},[3754],{"data":3755,"content":3756,"nodeType":433},{},[3757],{"data":3758,"marks":3759,"value":3760,"nodeType":437},{},[],"GET /api/status/{numeric_SID} (port :8443)",{"data":3762,"content":3763,"nodeType":3232},{},[3764,3774],{"data":3765,"content":3766,"nodeType":3221},{},[3767],{"data":3768,"content":3769,"nodeType":433},{},[3770],{"data":3771,"marks":3772,"value":3382,"nodeType":437},{},[3773],{"type":510},{"data":3775,"content":3776,"nodeType":3221},{},[3777],{"data":3778,"content":3779,"nodeType":433},{},[3780],{"data":3781,"marks":3782,"value":3783,"nodeType":437},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":3785,"content":3786,"nodeType":3232},{},[3787,3797],{"data":3788,"content":3789,"nodeType":3221},{},[3790],{"data":3791,"content":3792,"nodeType":433},{},[3793],{"data":3794,"marks":3795,"value":3606,"nodeType":437},{},[3796],{"type":510},{"data":3798,"content":3799,"nodeType":3221},{},[3800],{"data":3801,"content":3802,"nodeType":433},{},[3803],{"data":3804,"marks":3805,"value":3806,"nodeType":437},{},[],"auth[.]duemineral[.]uk",{"data":3808,"content":3812,"nodeType":548},{"target":3809},{"sys":3810},{"id":3811,"type":553,"linkType":554},"Y1AiT3dJRTXz64pb68kca",[],{"data":3814,"content":3815,"nodeType":557},{},[],{"data":3817,"content":3818,"nodeType":590},{},[3819],{"data":3820,"marks":3821,"value":3823,"nodeType":437},{},[3822],{"type":510},"“LINKID”",{"data":3825,"content":3826,"nodeType":3470},{},[3827,3850,3895,3925,3948],{"data":3828,"content":3829,"nodeType":3232},{},[3830,3840],{"data":3831,"content":3832,"nodeType":3221},{},[3833],{"data":3834,"content":3835,"nodeType":433},{},[3836],{"data":3837,"marks":3838,"value":3220,"nodeType":437},{},[3839],{"type":510},{"data":3841,"content":3842,"nodeType":3221},{},[3843],{"data":3844,"content":3845,"nodeType":433},{},[3846],{"data":3847,"marks":3848,"value":3849,"nodeType":437},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":3851,"content":3852,"nodeType":3232},{},[3853,3863],{"data":3854,"content":3855,"nodeType":3221},{},[3856],{"data":3857,"content":3858,"nodeType":433},{},[3859],{"data":3860,"marks":3861,"value":3246,"nodeType":437},{},[3862],{"type":510},{"data":3864,"content":3865,"nodeType":3221},{},[3866,3877,3884],{"data":3867,"content":3868,"nodeType":433},{},[3869,3873],{"data":3870,"marks":3871,"value":3722,"nodeType":437},{},[3872],{"type":510},{"data":3874,"marks":3875,"value":3876,"nodeType":437},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":3878,"content":3879,"nodeType":433},{},[3880],{"data":3881,"marks":3882,"value":3883,"nodeType":437},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":3885,"content":3886,"nodeType":433},{},[3887,3891],{"data":3888,"marks":3889,"value":3287,"nodeType":437},{},[3890],{"type":510},{"data":3892,"marks":3893,"value":3894,"nodeType":437},{},[]," axios/1.10.0 , axios/1.13.6",{"data":3896,"content":3897,"nodeType":3232},{},[3898,3908],{"data":3899,"content":3900,"nodeType":3221},{},[3901],{"data":3902,"content":3903,"nodeType":433},{},[3904],{"data":3905,"marks":3906,"value":3330,"nodeType":437},{},[3907],{"type":510},{"data":3909,"content":3910,"nodeType":3221},{},[3911,3918],{"data":3912,"content":3913,"nodeType":433},{},[3914],{"data":3915,"marks":3916,"value":3917,"nodeType":437},{},[],"POST /api/device/start",{"data":3919,"content":3920,"nodeType":433},{},[3921],{"data":3922,"marks":3923,"value":3924,"nodeType":437},{},[],"GET /api/device/status/{sessionId}",{"data":3926,"content":3927,"nodeType":3232},{},[3928,3938],{"data":3929,"content":3930,"nodeType":3221},{},[3931],{"data":3932,"content":3933,"nodeType":433},{},[3934],{"data":3935,"marks":3936,"value":3382,"nodeType":437},{},[3937],{"type":510},{"data":3939,"content":3940,"nodeType":3221},{},[3941],{"data":3942,"content":3943,"nodeType":433},{},[3944],{"data":3945,"marks":3946,"value":3947,"nodeType":437},{},[],"MS Teams meeting invitation (with interactive date/time picker), Adobe Acrobat Sign document review",{"data":3949,"content":3950,"nodeType":3232},{},[3951,3961],{"data":3952,"content":3953,"nodeType":3221},{},[3954],{"data":3955,"content":3956,"nodeType":433},{},[3957],{"data":3958,"marks":3959,"value":3606,"nodeType":437},{},[3960],{"type":510},{"data":3962,"content":3963,"nodeType":3221},{},[3964],{"data":3965,"content":3966,"nodeType":433},{},[3967],{"data":3968,"marks":3969,"value":3970,"nodeType":437},{},[],"sdtr-site[.]cfd",{"data":3972,"content":3976,"nodeType":548},{"target":3973},{"sys":3974},{"id":3975,"type":553,"linkType":554},"22hsIzlkptC2JTIUtbOuUn",[],{"data":3978,"content":3979,"nodeType":557},{},[],{"data":3981,"content":3982,"nodeType":590},{},[3983],{"data":3984,"marks":3985,"value":3987,"nodeType":437},{},[3986],{"type":510},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":3989,"content":3993,"nodeType":548},{"target":3990},{"sys":3991},{"id":3992,"type":553,"linkType":554},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":3995,"content":3996,"nodeType":3470},{},[3997,4020,4066,4089,4112],{"data":3998,"content":3999,"nodeType":3232},{},[4000,4010],{"data":4001,"content":4002,"nodeType":3221},{},[4003],{"data":4004,"content":4005,"nodeType":433},{},[4006],{"data":4007,"marks":4008,"value":3220,"nodeType":437},{},[4009],{"type":510},{"data":4011,"content":4012,"nodeType":3221},{},[4013],{"data":4014,"content":4015,"nodeType":433},{},[4016],{"data":4017,"marks":4018,"value":4019,"nodeType":437},{},[],"workers.dev",{"data":4021,"content":4022,"nodeType":3232},{},[4023,4033],{"data":4024,"content":4025,"nodeType":3221},{},[4026],{"data":4027,"content":4028,"nodeType":433},{},[4029],{"data":4030,"marks":4031,"value":3246,"nodeType":437},{},[4032],{"type":510},{"data":4034,"content":4035,"nodeType":3221},{},[4036,4047],{"data":4037,"content":4038,"nodeType":433},{},[4039,4043],{"data":4040,"marks":4041,"value":3722,"nodeType":437},{},[4042],{"type":510},{"data":4044,"marks":4045,"value":4046,"nodeType":437},{},[],"192.3.225.100 (HostPapa / ColoCrossing AS36352)",{"data":4048,"content":4049,"nodeType":433},{},[4050,4054,4057,4062],{"data":4051,"marks":4052,"value":3287,"nodeType":437},{},[4053],{"type":510},{"data":4055,"marks":4056,"value":3291,"nodeType":437},{},[],{"data":4058,"marks":4059,"value":4061,"nodeType":437},{},[4060],{"type":510}," ",{"data":4063,"marks":4064,"value":4065,"nodeType":437},{},[],"python-httpx/0.28.1",{"data":4067,"content":4068,"nodeType":3232},{},[4069,4079],{"data":4070,"content":4071,"nodeType":3221},{},[4072],{"data":4073,"content":4074,"nodeType":433},{},[4075],{"data":4076,"marks":4077,"value":3330,"nodeType":437},{},[4078],{"type":510},{"data":4080,"content":4081,"nodeType":3221},{},[4082],{"data":4083,"content":4084,"nodeType":433},{},[4085],{"data":4086,"marks":4087,"value":4088,"nodeType":437},{},[],"GET /landing/api/session-status?session_id=&token=",{"data":4090,"content":4091,"nodeType":3232},{},[4092,4102],{"data":4093,"content":4094,"nodeType":3221},{},[4095],{"data":4096,"content":4097,"nodeType":433},{},[4098],{"data":4099,"marks":4100,"value":3382,"nodeType":437},{},[4101],{"type":510},{"data":4103,"content":4104,"nodeType":3221},{},[4105],{"data":4106,"content":4107,"nodeType":433},{},[4108],{"data":4109,"marks":4110,"value":4111,"nodeType":437},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":4113,"content":4114,"nodeType":3232},{},[4115,4125],{"data":4116,"content":4117,"nodeType":3221},{},[4118],{"data":4119,"content":4120,"nodeType":433},{},[4121],{"data":4122,"marks":4123,"value":3606,"nodeType":437},{},[4124],{"type":510},{"data":4126,"content":4127,"nodeType":3221},{},[4128],{"data":4129,"content":4130,"nodeType":433},{},[4131],{"data":4132,"marks":4133,"value":4134,"nodeType":437},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":4136,"content":4140,"nodeType":548},{"target":4137},{"sys":4138},{"id":4139,"type":553,"linkType":554},"6szO6IKJ32usyxIKX1efZy",[],{"data":4142,"content":4146,"nodeType":548},{"target":4143},{"sys":4144},{"id":4145,"type":553,"linkType":554},"lEqV3RTMIY8y011lnhX7P",[],{"data":4148,"content":4149,"nodeType":557},{},[],{"data":4151,"content":4152,"nodeType":590},{},[4153],{"data":4154,"marks":4155,"value":4157,"nodeType":437},{},[4156],{"type":510},"“DOCUPOLL”",{"data":4159,"content":4160,"nodeType":3470},{},[4161,4184,4222,4259,4282],{"data":4162,"content":4163,"nodeType":3232},{},[4164,4174],{"data":4165,"content":4166,"nodeType":3221},{},[4167],{"data":4168,"content":4169,"nodeType":433},{},[4170],{"data":4171,"marks":4172,"value":3220,"nodeType":437},{},[4173],{"type":510},{"data":4175,"content":4176,"nodeType":3221},{},[4177],{"data":4178,"content":4179,"nodeType":433},{},[4180],{"data":4181,"marks":4182,"value":4183,"nodeType":437},{},[],"Github.io and workers.dev hosting",{"data":4185,"content":4186,"nodeType":3232},{},[4187,4197],{"data":4188,"content":4189,"nodeType":3221},{},[4190],{"data":4191,"content":4192,"nodeType":433},{},[4193],{"data":4194,"marks":4195,"value":3246,"nodeType":437},{},[4196],{"type":510},{"data":4198,"content":4199,"nodeType":3221},{},[4200,4211],{"data":4201,"content":4202,"nodeType":433},{},[4203,4207],{"data":4204,"marks":4205,"value":3722,"nodeType":437},{},[4206],{"type":510},{"data":4208,"marks":4209,"value":4210,"nodeType":437},{},[],"144.172.103.240 (FranTech Solutions / RouterHosting / Cloudzy AS14956)",{"data":4212,"content":4213,"nodeType":433},{},[4214,4218],{"data":4215,"marks":4216,"value":3287,"nodeType":437},{},[4217],{"type":510},{"data":4219,"marks":4220,"value":4221,"nodeType":437},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042",{"data":4223,"content":4224,"nodeType":3232},{},[4225,4235],{"data":4226,"content":4227,"nodeType":3221},{},[4228],{"data":4229,"content":4230,"nodeType":433},{},[4231],{"data":4232,"marks":4233,"value":3330,"nodeType":437},{},[4234],{"type":510},{"data":4236,"content":4237,"nodeType":3221},{},[4238,4245,4252],{"data":4239,"content":4240,"nodeType":433},{},[4241],{"data":4242,"marks":4243,"value":4244,"nodeType":437},{},[],"POST /api/v1/landing-pages/public/{slug}/init",{"data":4246,"content":4247,"nodeType":433},{},[4248],{"data":4249,"marks":4250,"value":4251,"nodeType":437},{},[],"POST .../poll",{"data":4253,"content":4254,"nodeType":433},{},[4255],{"data":4256,"marks":4257,"value":4258,"nodeType":437},{},[],"POST .../track",{"data":4260,"content":4261,"nodeType":3232},{},[4262,4272],{"data":4263,"content":4264,"nodeType":3221},{},[4265],{"data":4266,"content":4267,"nodeType":433},{},[4268],{"data":4269,"marks":4270,"value":3382,"nodeType":437},{},[4271],{"type":510},{"data":4273,"content":4274,"nodeType":3221},{},[4275],{"data":4276,"content":4277,"nodeType":433},{},[4278],{"data":4279,"marks":4280,"value":4281,"nodeType":437},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":4283,"content":4284,"nodeType":3232},{},[4285,4295],{"data":4286,"content":4287,"nodeType":3221},{},[4288],{"data":4289,"content":4290,"nodeType":433},{},[4291],{"data":4292,"marks":4293,"value":3606,"nodeType":437},{},[4294],{"type":510},{"data":4296,"content":4297,"nodeType":3221},{},[4298],{"data":4299,"content":4300,"nodeType":433},{},[4301],{"data":4302,"marks":4303,"value":4304,"nodeType":437},{},[],"docufirmar[.]github.io",{"data":4306,"content":4310,"nodeType":548},{"target":4307},{"sys":4308},{"id":4309,"type":553,"linkType":554},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":4312,"content":4313,"nodeType":557},{},[],{"data":4315,"content":4316,"nodeType":590},{},[4317],{"data":4318,"marks":4319,"value":4321,"nodeType":437},{},[4320],{"type":510},"“FLOW_TOKEN”",{"data":4323,"content":4324,"nodeType":3470},{},[4325,4347,4392,4422,4445],{"data":4326,"content":4327,"nodeType":3232},{},[4328,4338],{"data":4329,"content":4330,"nodeType":3221},{},[4331],{"data":4332,"content":4333,"nodeType":433},{},[4334],{"data":4335,"marks":4336,"value":3220,"nodeType":437},{},[4337],{"type":510},{"data":4339,"content":4340,"nodeType":3221},{},[4341],{"data":4342,"content":4343,"nodeType":433},{},[4344],{"data":4345,"marks":4346,"value":4019,"nodeType":437},{},[],{"data":4348,"content":4349,"nodeType":3232},{},[4350,4360],{"data":4351,"content":4352,"nodeType":3221},{},[4353],{"data":4354,"content":4355,"nodeType":433},{},[4356],{"data":4357,"marks":4358,"value":3246,"nodeType":437},{},[4359],{"type":510},{"data":4361,"content":4362,"nodeType":3221},{},[4363,4374],{"data":4364,"content":4365,"nodeType":433},{},[4366,4370],{"data":4367,"marks":4368,"value":3722,"nodeType":437},{},[4369],{"type":510},{"data":4371,"marks":4372,"value":4373,"nodeType":437},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":4375,"content":4376,"nodeType":433},{},[4377,4381,4384,4388],{"data":4378,"marks":4379,"value":3287,"nodeType":437},{},[4380],{"type":510},{"data":4382,"marks":4383,"value":3291,"nodeType":437},{},[],{"data":4385,"marks":4386,"value":4061,"nodeType":437},{},[4387],{"type":510},{"data":4389,"marks":4390,"value":4391,"nodeType":437},{},[],"(null)",{"data":4393,"content":4394,"nodeType":3232},{},[4395,4405],{"data":4396,"content":4397,"nodeType":3221},{},[4398],{"data":4399,"content":4400,"nodeType":433},{},[4401],{"data":4402,"marks":4403,"value":3330,"nodeType":437},{},[4404],{"type":510},{"data":4406,"content":4407,"nodeType":3221},{},[4408,4415],{"data":4409,"content":4410,"nodeType":433},{},[4411],{"data":4412,"marks":4413,"value":4414,"nodeType":437},{},[],"POST /api/handler.php ",{"data":4416,"content":4417,"nodeType":433},{},[4418],{"data":4419,"marks":4420,"value":4421,"nodeType":437},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":4423,"content":4424,"nodeType":3232},{},[4425,4435],{"data":4426,"content":4427,"nodeType":3221},{},[4428],{"data":4429,"content":4430,"nodeType":433},{},[4431],{"data":4432,"marks":4433,"value":3382,"nodeType":437},{},[4434],{"type":510},{"data":4436,"content":4437,"nodeType":3221},{},[4438],{"data":4439,"content":4440,"nodeType":433},{},[4441],{"data":4442,"marks":4443,"value":4444,"nodeType":437},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":4446,"content":4447,"nodeType":3232},{},[4448,4458],{"data":4449,"content":4450,"nodeType":3221},{},[4451],{"data":4452,"content":4453,"nodeType":433},{},[4454],{"data":4455,"marks":4456,"value":3606,"nodeType":437},{},[4457],{"type":510},{"data":4459,"content":4460,"nodeType":3221},{},[4461],{"data":4462,"content":4463,"nodeType":433},{},[4464],{"data":4465,"marks":4466,"value":4467,"nodeType":437},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":4469,"content":4473,"nodeType":548},{"target":4470},{"sys":4471},{"id":4472,"type":553,"linkType":554},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":4475,"content":4476,"nodeType":557},{},[],{"data":4478,"content":4479,"nodeType":590},{},[4480],{"data":4481,"marks":4482,"value":4484,"nodeType":437},{},[4483],{"type":510},"“PAPRIKA”",{"data":4486,"content":4487,"nodeType":3470},{},[4488,4511,4534,4557],{"data":4489,"content":4490,"nodeType":3232},{},[4491,4501],{"data":4492,"content":4493,"nodeType":3221},{},[4494],{"data":4495,"content":4496,"nodeType":433},{},[4497],{"data":4498,"marks":4499,"value":3220,"nodeType":437},{},[4500],{"type":510},{"data":4502,"content":4503,"nodeType":3221},{},[4504],{"data":4505,"content":4506,"nodeType":433},{},[4507],{"data":4508,"marks":4509,"value":4510,"nodeType":437},{},[],"AWS S3 hosting",{"data":4512,"content":4513,"nodeType":3232},{},[4514,4524],{"data":4515,"content":4516,"nodeType":3221},{},[4517],{"data":4518,"content":4519,"nodeType":433},{},[4520],{"data":4521,"marks":4522,"value":3330,"nodeType":437},{},[4523],{"type":510},{"data":4525,"content":4526,"nodeType":3221},{},[4527],{"data":4528,"content":4529,"nodeType":433},{},[4530],{"data":4531,"marks":4532,"value":4533,"nodeType":437},{},[],"POST /api/v1/loader",{"data":4535,"content":4536,"nodeType":3232},{},[4537,4547],{"data":4538,"content":4539,"nodeType":3221},{},[4540],{"data":4541,"content":4542,"nodeType":433},{},[4543],{"data":4544,"marks":4545,"value":3382,"nodeType":437},{},[4546],{"type":510},{"data":4548,"content":4549,"nodeType":3221},{},[4550],{"data":4551,"content":4552,"nodeType":433},{},[4553],{"data":4554,"marks":4555,"value":4556,"nodeType":437},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":4558,"content":4559,"nodeType":3232},{},[4560,4570],{"data":4561,"content":4562,"nodeType":3221},{},[4563],{"data":4564,"content":4565,"nodeType":433},{},[4566],{"data":4567,"marks":4568,"value":3606,"nodeType":437},{},[4569],{"type":510},{"data":4571,"content":4572,"nodeType":3221},{},[4573],{"data":4574,"content":4575,"nodeType":433},{},[4576],{"data":4577,"marks":4578,"value":4579,"nodeType":437},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":4581,"content":4585,"nodeType":548},{"target":4582},{"sys":4583},{"id":4584,"type":553,"linkType":554},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":4587,"content":4588,"nodeType":557},{},[],{"data":4590,"content":4591,"nodeType":590},{},[4592],{"data":4593,"marks":4594,"value":4596,"nodeType":437},{},[4595],{"type":510},"“DCSTATUS”",{"data":4598,"content":4599,"nodeType":3470},{},[4600,4622,4645,4668],{"data":4601,"content":4602,"nodeType":3232},{},[4603,4613],{"data":4604,"content":4605,"nodeType":3221},{},[4606],{"data":4607,"content":4608,"nodeType":433},{},[4609],{"data":4610,"marks":4611,"value":3220,"nodeType":437},{},[4612],{"type":510},{"data":4614,"content":4615,"nodeType":3221},{},[4616],{"data":4617,"content":4618,"nodeType":433},{},[4619],{"data":4620,"marks":4621,"value":3507,"nodeType":437},{},[],{"data":4623,"content":4624,"nodeType":3232},{},[4625,4635],{"data":4626,"content":4627,"nodeType":3221},{},[4628],{"data":4629,"content":4630,"nodeType":433},{},[4631],{"data":4632,"marks":4633,"value":3330,"nodeType":437},{},[4634],{"type":510},{"data":4636,"content":4637,"nodeType":3221},{},[4638],{"data":4639,"content":4640,"nodeType":433},{},[4641],{"data":4642,"marks":4643,"value":4644,"nodeType":437},{},[],"GET /dc/status/{base64url_sid}",{"data":4646,"content":4647,"nodeType":3232},{},[4648,4658],{"data":4649,"content":4650,"nodeType":3221},{},[4651],{"data":4652,"content":4653,"nodeType":433},{},[4654],{"data":4655,"marks":4656,"value":3382,"nodeType":437},{},[4657],{"type":510},{"data":4659,"content":4660,"nodeType":3221},{},[4661],{"data":4662,"content":4663,"nodeType":433},{},[4664],{"data":4665,"marks":4666,"value":4667,"nodeType":437},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":4669,"content":4670,"nodeType":3232},{},[4671,4681],{"data":4672,"content":4673,"nodeType":3221},{},[4674],{"data":4675,"content":4676,"nodeType":433},{},[4677],{"data":4678,"marks":4679,"value":3606,"nodeType":437},{},[4680],{"type":510},{"data":4682,"content":4683,"nodeType":3221},{},[4684],{"data":4685,"content":4686,"nodeType":433},{},[4687],{"data":4688,"marks":4689,"value":4690,"nodeType":437},{},[],"owa[.]apmmacleans[.]ca",{"data":4692,"content":4696,"nodeType":548},{"target":4693},{"sys":4694},{"id":4695,"type":553,"linkType":554},"ugYhHeXY1lQdKooALmrIs",[],{"data":4698,"content":4699,"nodeType":557},{},[],{"data":4701,"content":4702,"nodeType":590},{},[4703],{"data":4704,"marks":4705,"value":4707,"nodeType":437},{},[4706],{"type":510},"“DOLCE”",{"data":4709,"content":4713,"nodeType":548},{"target":4710},{"sys":4711},{"id":4712,"type":553,"linkType":554},"7TzU6kk01Un45NB0buEz2",[],{"data":4715,"content":4716,"nodeType":3470},{},[4717,4740,4778,4801,4824],{"data":4718,"content":4719,"nodeType":3232},{},[4720,4730],{"data":4721,"content":4722,"nodeType":3221},{},[4723],{"data":4724,"content":4725,"nodeType":433},{},[4726],{"data":4727,"marks":4728,"value":3220,"nodeType":437},{},[4729],{"type":510},{"data":4731,"content":4732,"nodeType":3221},{},[4733],{"data":4734,"content":4735,"nodeType":433},{},[4736],{"data":4737,"marks":4738,"value":4739,"nodeType":437},{},[],"Microsoft PowerApps hosting",{"data":4741,"content":4742,"nodeType":3232},{},[4743,4753],{"data":4744,"content":4745,"nodeType":3221},{},[4746],{"data":4747,"content":4748,"nodeType":433},{},[4749],{"data":4750,"marks":4751,"value":3246,"nodeType":437},{},[4752],{"type":510},{"data":4754,"content":4755,"nodeType":3221},{},[4756,4767],{"data":4757,"content":4758,"nodeType":433},{},[4759,4763],{"data":4760,"marks":4761,"value":3722,"nodeType":437},{},[4762],{"type":510},{"data":4764,"marks":4765,"value":4766,"nodeType":437},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":4768,"content":4769,"nodeType":433},{},[4770,4774],{"data":4771,"marks":4772,"value":3287,"nodeType":437},{},[4773],{"type":510},{"data":4775,"marks":4776,"value":4777,"nodeType":437},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36",{"data":4779,"content":4780,"nodeType":3232},{},[4781,4791],{"data":4782,"content":4783,"nodeType":3221},{},[4784],{"data":4785,"content":4786,"nodeType":433},{},[4787],{"data":4788,"marks":4789,"value":3330,"nodeType":437},{},[4790],{"type":510},{"data":4792,"content":4793,"nodeType":3221},{},[4794],{"data":4795,"content":4796,"nodeType":433},{},[4797],{"data":4798,"marks":4799,"value":4800,"nodeType":437},{},[],"GET /api/generatecode (CloudFront)",{"data":4802,"content":4803,"nodeType":3232},{},[4804,4814],{"data":4805,"content":4806,"nodeType":3221},{},[4807],{"data":4808,"content":4809,"nodeType":433},{},[4810],{"data":4811,"marks":4812,"value":3382,"nodeType":437},{},[4813],{"type":510},{"data":4815,"content":4816,"nodeType":3221},{},[4817],{"data":4818,"content":4819,"nodeType":433},{},[4820],{"data":4821,"marks":4822,"value":4823,"nodeType":437},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":4825,"content":4826,"nodeType":3232},{},[4827,4837],{"data":4828,"content":4829,"nodeType":3221},{},[4830],{"data":4831,"content":4832,"nodeType":433},{},[4833],{"data":4834,"marks":4835,"value":3606,"nodeType":437},{},[4836],{"type":510},{"data":4838,"content":4839,"nodeType":3221},{},[4840],{"data":4841,"content":4842,"nodeType":433},{},[4843],{"data":4844,"marks":4845,"value":4846,"nodeType":437},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":4848,"content":4852,"nodeType":548},{"target":4849},{"sys":4850},{"id":4851,"type":553,"linkType":554},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":4854,"content":4855,"nodeType":557},{},[],{"data":4857,"content":4858,"nodeType":590},{},[4859],{"data":4860,"marks":4861,"value":4863,"nodeType":437},{},[4862],{"type":510},"Venom",{"data":4865,"content":4866,"nodeType":3470},{},[4867,4890],{"data":4868,"content":4869,"nodeType":3232},{},[4870,4880],{"data":4871,"content":4872,"nodeType":3221},{},[4873],{"data":4874,"content":4875,"nodeType":433},{},[4876],{"data":4877,"marks":4878,"value":3330,"nodeType":437},{},[4879],{"type":510},{"data":4881,"content":4882,"nodeType":3221},{},[4883],{"data":4884,"content":4885,"nodeType":433},{},[4886],{"data":4887,"marks":4888,"value":4889,"nodeType":437},{},[],"POST /token/api/device/start\nGET /token/api/device/status/{sessionId}",{"data":4891,"content":4892,"nodeType":3232},{},[4893,4903],{"data":4894,"content":4895,"nodeType":3221},{},[4896],{"data":4897,"content":4898,"nodeType":433},{},[4899],{"data":4900,"marks":4901,"value":3382,"nodeType":437},{},[4902],{"type":510},{"data":4904,"content":4905,"nodeType":3221},{},[4906],{"data":4907,"content":4908,"nodeType":433},{},[4909],{"data":4910,"marks":4911,"value":4912,"nodeType":437},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":4914,"content":4918,"nodeType":548},{"target":4915},{"sys":4916},{"id":4917,"type":553,"linkType":554},"79C3fces0hgTdf3G68cIrf",[],{"data":4920,"content":4921,"nodeType":557},{},[],{"data":4923,"content":4924,"nodeType":590},{},[4925],{"data":4926,"marks":4927,"value":4929,"nodeType":437},{},[4928],{"type":510},"Tycoon2FA",{"data":4931,"content":4932,"nodeType":3470},{},[4933,4963,5000,5023,5046],{"data":4934,"content":4935,"nodeType":3232},{},[4936,4946],{"data":4937,"content":4938,"nodeType":3221},{},[4939],{"data":4940,"content":4941,"nodeType":433},{},[4942],{"data":4943,"marks":4944,"value":3220,"nodeType":437},{},[4945],{"type":510},{"data":4947,"content":4948,"nodeType":3221},{},[4949,4956],{"data":4950,"content":4951,"nodeType":433},{},[4952],{"data":4953,"marks":4954,"value":4955,"nodeType":437},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":4957,"content":4958,"nodeType":433},{},[4959],{"data":4960,"marks":4961,"value":4962,"nodeType":437},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct/?encoded query",{"data":4964,"content":4965,"nodeType":3232},{},[4966,4976],{"data":4967,"content":4968,"nodeType":3221},{},[4969],{"data":4970,"content":4971,"nodeType":433},{},[4972],{"data":4973,"marks":4974,"value":3246,"nodeType":437},{},[4975],{"type":510},{"data":4977,"content":4978,"nodeType":3221},{},[4979,4990],{"data":4980,"content":4981,"nodeType":433},{},[4982,4986],{"data":4983,"marks":4984,"value":3722,"nodeType":437},{},[4985],{"type":510},{"data":4987,"marks":4988,"value":4989,"nodeType":437},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":4991,"content":4992,"nodeType":433},{},[4993,4997],{"data":4994,"marks":4995,"value":3287,"nodeType":437},{},[4996],{"type":510},{"data":4998,"marks":4999,"value":3546,"nodeType":437},{},[],{"data":5001,"content":5002,"nodeType":3232},{},[5003,5013],{"data":5004,"content":5005,"nodeType":3221},{},[5006],{"data":5007,"content":5008,"nodeType":433},{},[5009],{"data":5010,"marks":5011,"value":3330,"nodeType":437},{},[5012],{"type":510},{"data":5014,"content":5015,"nodeType":3221},{},[5016],{"data":5017,"content":5018,"nodeType":433},{},[5019],{"data":5020,"marks":5021,"value":5022,"nodeType":437},{},[],"GET /api/session/{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST /api/device-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":5024,"content":5025,"nodeType":3232},{},[5026,5036],{"data":5027,"content":5028,"nodeType":3221},{},[5029],{"data":5030,"content":5031,"nodeType":433},{},[5032],{"data":5033,"marks":5034,"value":3382,"nodeType":437},{},[5035],{"type":510},{"data":5037,"content":5038,"nodeType":3221},{},[5039],{"data":5040,"content":5041,"nodeType":433},{},[5042],{"data":5043,"marks":5044,"value":5045,"nodeType":437},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":5047,"content":5048,"nodeType":3232},{},[5049,5059],{"data":5050,"content":5051,"nodeType":3221},{},[5052],{"data":5053,"content":5054,"nodeType":433},{},[5055],{"data":5056,"marks":5057,"value":3606,"nodeType":437},{},[5058],{"type":510},{"data":5060,"content":5061,"nodeType":3221},{},[5062],{"data":5063,"content":5064,"nodeType":433},{},[5065],{"data":5066,"marks":5067,"value":5068,"nodeType":437},{},[],"afriqbeauglobal[.]com/homepage/index[.]html",{"data":5070,"content":5073,"nodeType":548},{"target":5071},{"sys":5072},{"id":1885,"type":553,"linkType":554},[],{"data":5075,"content":5076,"nodeType":557},{},[],{"data":5078,"content":5079,"nodeType":590},{},[5080],{"data":5081,"marks":5082,"value":5084,"nodeType":437},{},[5083],{"type":510},"\"CYB3R\"",{"data":5086,"content":5087,"nodeType":3470},{},[5088,5111,5149,5171,5194],{"data":5089,"content":5090,"nodeType":3232},{},[5091,5101],{"data":5092,"content":5093,"nodeType":3221},{},[5094],{"data":5095,"content":5096,"nodeType":433},{},[5097],{"data":5098,"marks":5099,"value":3220,"nodeType":437},{},[5100],{"type":510},{"data":5102,"content":5103,"nodeType":3221},{},[5104],{"data":5105,"content":5106,"nodeType":433},{},[5107],{"data":5108,"marks":5109,"value":5110,"nodeType":437},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":5112,"content":5113,"nodeType":3232},{},[5114,5124],{"data":5115,"content":5116,"nodeType":3221},{},[5117],{"data":5118,"content":5119,"nodeType":433},{},[5120],{"data":5121,"marks":5122,"value":3246,"nodeType":437},{},[5123],{"type":510},{"data":5125,"content":5126,"nodeType":3221},{},[5127,5138],{"data":5128,"content":5129,"nodeType":433},{},[5130,5134],{"data":5131,"marks":5132,"value":3722,"nodeType":437},{},[5133],{"type":510},{"data":5135,"marks":5136,"value":5137,"nodeType":437},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":5139,"content":5140,"nodeType":433},{},[5141,5145],{"data":5142,"marks":5143,"value":3287,"nodeType":437},{},[5144],{"type":510},{"data":5146,"marks":5147,"value":5148,"nodeType":437},{},[]," axios/1.13.6",{"data":5150,"content":5151,"nodeType":3232},{},[5152,5162],{"data":5153,"content":5154,"nodeType":3221},{},[5155],{"data":5156,"content":5157,"nodeType":433},{},[5158],{"data":5159,"marks":5160,"value":3330,"nodeType":437},{},[5161],{"type":510},{"data":5163,"content":5164,"nodeType":3221},{},[5165],{"data":5166,"content":5167,"nodeType":433},{},[5168],{"data":5169,"marks":5170,"value":5022,"nodeType":437},{},[],{"data":5172,"content":5173,"nodeType":3232},{},[5174,5184],{"data":5175,"content":5176,"nodeType":3221},{},[5177],{"data":5178,"content":5179,"nodeType":433},{},[5180],{"data":5181,"marks":5182,"value":3382,"nodeType":437},{},[5183],{"type":510},{"data":5185,"content":5186,"nodeType":3221},{},[5187],{"data":5188,"content":5189,"nodeType":433},{},[5190],{"data":5191,"marks":5192,"value":5193,"nodeType":437},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN/ESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":5195,"content":5196,"nodeType":3232},{},[5197,5207],{"data":5198,"content":5199,"nodeType":3221},{},[5200],{"data":5201,"content":5202,"nodeType":433},{},[5203],{"data":5204,"marks":5205,"value":3606,"nodeType":437},{},[5206],{"type":510},{"data":5208,"content":5209,"nodeType":3221},{},[5210],{"data":5211,"content":5212,"nodeType":433},{},[5213],{"data":5214,"marks":5215,"value":5216,"nodeType":437},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":5218,"content":5222,"nodeType":548},{"target":5219},{"sys":5220},{"id":5221,"type":553,"linkType":554},"5EU0QNteiQcYybKG1W1cS3",[],{"data":5224,"content":5225,"nodeType":557},{},[],{"data":5227,"content":5228,"nodeType":561},{},[5229],{"data":5230,"marks":5231,"value":5233,"nodeType":437},{},[5232],{"type":510},"Device code phishing under the hood",{"data":5235,"content":5236,"nodeType":433},{},[5237,5241],{"data":5238,"marks":5239,"value":5240,"nodeType":437},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":5242,"marks":5243,"value":5245,"nodeType":437},{},[5244],{"type":510},"The attacker now has API access to the victim's account. ",{"data":5247,"content":5248,"nodeType":433},{},[5249],{"data":5250,"marks":5251,"value":5252,"nodeType":437},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":5254,"content":5258,"nodeType":548},{"target":5255},{"sys":5256},{"id":5257,"type":553,"linkType":554},"4WtQR2xsE236yoyhSXj58Z",[],{"data":5260,"content":5264,"nodeType":548},{"target":5261},{"sys":5262},{"id":5263,"type":553,"linkType":554},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":5266,"content":5267,"nodeType":433},{},[5268],{"data":5269,"marks":5270,"value":5271,"nodeType":437},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":5273,"content":5274,"nodeType":433},{},[5275,5279,5284,5288],{"data":5276,"marks":5277,"value":5278,"nodeType":437},{},[],"Critically, the initial request to generate a device code is typically ",{"data":5280,"marks":5281,"value":5283,"nodeType":437},{},[5282],{"type":510},"unauthenticated",{"data":5285,"marks":5286,"value":5287,"nodeType":437},{},[]," across all providers — ",{"data":5289,"marks":5290,"value":5292,"nodeType":437},{},[5291],{"type":510},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":5294,"content":5295,"nodeType":433},{},[5296,5300,5305],{"data":5297,"marks":5298,"value":5299,"nodeType":437},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":5301,"marks":5302,"value":5304,"nodeType":437},{},[5303],{"type":510},"legitimate device code login page",{"data":5306,"marks":5307,"value":5308,"nodeType":437},{},[]," for that app and issues the tokens to the attacker.",{"data":5310,"content":5314,"nodeType":548},{"target":5311},{"sys":5312},{"id":5313,"type":553,"linkType":554},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":5316,"content":5317,"nodeType":557},{},[],{"data":5319,"content":5320,"nodeType":561},{},[5321],{"data":5322,"marks":5323,"value":5325,"nodeType":437},{},[5324],{"type":510},"Why device code phishing is so dangerous",{"data":5327,"content":5328,"nodeType":590},{},[5329],{"data":5330,"marks":5331,"value":5333,"nodeType":437},{},[5332],{"type":510},"Device code phishing bypasses authentication controls (including passkeys)",{"data":5335,"content":5336,"nodeType":433},{},[5337,5341,5346,5350],{"data":5338,"marks":5339,"value":5340,"nodeType":437},{},[],"A device code phishing attack ",{"data":5342,"marks":5343,"value":5345,"nodeType":437},{},[5344],{"type":510},"cannot be prevented with authentication controls",{"data":5347,"marks":5348,"value":5349,"nodeType":437},{},[],". This includes all forms of MFA and ",{"data":5351,"marks":5352,"value":5354,"nodeType":437},{},[5353],{"type":510},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":5356,"content":5357,"nodeType":433},{},[5358,5363,5367,5372],{"data":5359,"marks":5360,"value":5362,"nodeType":437},{},[5361],{"type":510},"The device code authorization is effectively performed post-authentication. ",{"data":5364,"marks":5365,"value":5366,"nodeType":437},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":5368,"marks":5369,"value":5371,"nodeType":437},{},[5370],{"type":510},"No password or MFA required. ",{"data":5373,"marks":5374,"value":5375,"nodeType":437},{},[],"You can see an example in the video below.",{"data":5377,"content":5380,"nodeType":548},{"target":5378},{"sys":5379},{"id":4309,"type":553,"linkType":554},[],{"data":5382,"content":5383,"nodeType":433},{},[5384],{"data":5385,"marks":5386,"value":5387,"nodeType":437},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":5389,"content":5390,"nodeType":433},{},[5391],{"data":5392,"marks":5393,"value":5394,"nodeType":437},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":5396,"content":5397,"nodeType":590},{},[5398],{"data":5399,"marks":5400,"value":5402,"nodeType":437},{},[5401],{"type":510},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":5404,"content":5405,"nodeType":433},{},[5406],{"data":5407,"marks":5408,"value":5409,"nodeType":437},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":5411,"content":5412,"nodeType":433},{},[5413],{"data":5414,"marks":5415,"value":5416,"nodeType":437},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":5418,"content":5419,"nodeType":433},{},[5420],{"data":5421,"marks":5422,"value":5423,"nodeType":437},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":5425,"content":5426,"nodeType":590},{},[5427],{"data":5428,"marks":5429,"value":5431,"nodeType":437},{},[5430],{"type":510},"Multiple apps are vulnerable, with different risk profiles",{"data":5433,"content":5434,"nodeType":433},{},[5435],{"data":5436,"marks":5437,"value":5438,"nodeType":437},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":5440,"content":5441,"nodeType":2377},{},[5442,5457,5471],{"data":5443,"content":5444,"nodeType":2381},{},[5445],{"data":5446,"content":5447,"nodeType":433},{},[5448,5453],{"data":5449,"marks":5450,"value":5452,"nodeType":437},{},[5451],{"type":510},"Google Workspace ",{"data":5454,"marks":5455,"value":5456,"nodeType":437},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":5458,"content":5459,"nodeType":2381},{},[5460],{"data":5461,"content":5462,"nodeType":433},{},[5463,5467],{"data":5464,"marks":5465,"value":2923,"nodeType":437},{},[5466],{"type":510},{"data":5468,"marks":5469,"value":5470,"nodeType":437},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI/PRT escalation paths. ",{"data":5472,"content":5473,"nodeType":2381},{},[5474],{"data":5475,"content":5476,"nodeType":433},{},[5477,5481,5486],{"data":5478,"marks":5479,"value":5480,"nodeType":437},{},[],"Apps like ",{"data":5482,"marks":5483,"value":5485,"nodeType":437},{},[5484],{"type":510},"GitHub",{"data":5487,"marks":5488,"value":5489,"nodeType":437},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":5491,"content":5495,"nodeType":548},{"target":5492},{"sys":5493},{"id":5494,"type":553,"linkType":554},"ejNSC76jge1p1zzz9wwiG",[],{"data":5497,"content":5498,"nodeType":557},{},[],{"data":5500,"content":5501,"nodeType":561},{},[5502],{"data":5503,"marks":5504,"value":5506,"nodeType":437},{},[5505],{"type":510},"Security recommendations",{"data":5508,"content":5509,"nodeType":433},{},[5510],{"data":5511,"marks":5512,"value":5513,"nodeType":437},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":5515,"content":5516,"nodeType":433},{},[5517],{"data":5518,"marks":5519,"value":5520,"nodeType":437},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":5522,"content":5523,"nodeType":433},{},[5524,5528,5537,5541,5546,5550,5555,5559,5564],{"data":5525,"marks":5526,"value":5527,"nodeType":437},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":5529,"content":5531,"nodeType":456},{"uri":5530},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758",[5532],{"data":5533,"marks":5534,"value":5536,"nodeType":437},{},[5535],{"type":483},"Microsoft now explicitly recommends",{"data":5538,"marks":5539,"value":5540,"nodeType":437},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":5542,"marks":5543,"value":5545,"nodeType":437},{},[5544],{"type":510},"Authentication Flows",{"data":5547,"marks":5548,"value":5549,"nodeType":437},{},[]," condition to block ",{"data":5551,"marks":5552,"value":5554,"nodeType":437},{},[5553],{"type":510},"Device Code Flow",{"data":5556,"marks":5557,"value":5558,"nodeType":437},{},[],", and set the grant control to ",{"data":5560,"marks":5561,"value":5563,"nodeType":437},{},[5562],{"type":510},"Block Access",{"data":5565,"marks":5566,"value":5567,"nodeType":437},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":5569,"content":5573,"nodeType":548},{"target":5570},{"sys":5571},{"id":5572,"type":553,"linkType":554},"mQIj2o9xRzkZYKNmanB25",[],{"data":5575,"content":5576,"nodeType":433},{},[5577],{"data":5578,"marks":5579,"value":5580,"nodeType":437},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":5582,"content":5583,"nodeType":557},{},[],{"data":5585,"content":5586,"nodeType":561},{},[5587],{"data":5588,"marks":5589,"value":5591,"nodeType":437},{},[5590],{"type":510},"How Push Security can help",{"data":5593,"content":5594,"nodeType":433},{},[5595],{"data":5596,"marks":5597,"value":5598,"nodeType":437},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":5600,"content":5601,"nodeType":433},{},[5602],{"data":5603,"marks":5604,"value":5605,"nodeType":437},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":5607,"content":5608,"nodeType":433},{},[5609,5613,5622],{"data":5610,"marks":5611,"value":5612,"nodeType":437},{},[],"Using Push you can also ",{"data":5614,"content":5616,"nodeType":456},{"uri":5615},"https://pushsecurity.com/help/can-i-use-push-to-help-protect-against-device-code-phishing-scenarios/",[5617],{"data":5618,"marks":5619,"value":5621,"nodeType":437},{},[5620],{"type":483},"configure in-browser warnings",{"data":5623,"marks":5624,"value":5625,"nodeType":437},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":5627,"content":5631,"nodeType":548},{"target":5628},{"sys":5629},{"id":5630,"type":553,"linkType":554},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":5633,"content":5634,"nodeType":433},{},[5635],{"data":5636,"marks":5637,"value":5638,"nodeType":437},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":5640,"content":5641,"nodeType":590},{},[5642],{"data":5643,"marks":5644,"value":5646,"nodeType":437},{},[5645],{"type":510},"Learn more about Push",{"data":5648,"content":5649,"nodeType":433},{},[5650],{"data":5651,"marks":5652,"value":5653,"nodeType":437},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":5655,"content":5656,"nodeType":433},{},[5657,5661,5670,5673,5682,5686,5695],{"data":5658,"marks":5659,"value":5660,"nodeType":437},{},[],"To learn more about Push, ",{"data":5662,"content":5664,"nodeType":456},{"uri":5663},"https://pushsecurity.com/resources/product-brochure",[5665],{"data":5666,"marks":5667,"value":5669,"nodeType":437},{},[5668],{"type":483},"check out our latest product overview",{"data":5671,"marks":5672,"value":1924,"nodeType":437},{},[],{"data":5674,"content":5676,"nodeType":456},{"uri":5675},"https://pushsecurity.com/product-demo/",[5677],{"data":5678,"marks":5679,"value":5681,"nodeType":437},{},[5680],{"type":483},"view our demo library",{"data":5683,"marks":5684,"value":5685,"nodeType":437},{},[],", or ",{"data":5687,"content":5689,"nodeType":456},{"uri":5688},"https://pushsecurity.com/demo",[5690],{"data":5691,"marks":5692,"value":5694,"nodeType":437},{},[5693],{"type":483},"book some time with one of our team for a live demo",{"data":5696,"marks":5697,"value":1623,"nodeType":437},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z","device-code-phishing",{"items":5703},[5704,5706],{"sys":5705,"name":2679},{"id":2678},{"sys":5707,"name":2683},{"id":2682},{"items":5709},[5710],{"fullName":420,"firstName":421,"jobTitle":422,"profilePicture":5711},{"url":426},{"__typename":1370,"sys":5713,"content":5715,"title":6277,"synopsis":6278,"hashTags":59,"publishedDate":6279,"slug":6280,"tagsCollection":6281,"authorsCollection":6287},{"id":5714},"27Z1JlNtpGTPyarh393sHK",{"json":5716},{"data":5717,"content":5718,"nodeType":429},{},[5719,5737,5744,5750,5757,5763,5783,5789,5795,5798,5806,5826,5832,5838,5844,5861,5868,5876,5883,5890,5897,5900,5908,5926,5949,5954,5960,5967,5974,5981,5984,5992,6010,6043,6050,6056,6059,6067,6074,6077,6084,6091,6099,6118,6138,6145,6151,6159,6166,6173,6176,6184,6191,6197,6214,6220,6227,6234,6241],{"data":5720,"content":5721,"nodeType":433},{},[5722,5726,5733],{"data":5723,"marks":5724,"value":5725,"nodeType":437},{},[],"In December 2025, we uncovered a state-sponsored campaign linked to Russian state-affiliated APT29 that used a new technique we called ",{"data":5727,"content":5728,"nodeType":456},{"uri":525},[5729],{"data":5730,"marks":5731,"value":711,"nodeType":437},{},[5732],{"type":483},{"data":5734,"marks":5735,"value":5736,"nodeType":437},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. Effectively, ConsentFix is a browser-native attack that results in account takeover, without the downside of needing to touch the endpoint like typical ClickFix (really, the point that it's most likely to be detected and blocked). ",{"data":5738,"content":5739,"nodeType":433},{},[5740],{"data":5741,"marks":5742,"value":5743,"nodeType":437},{},[],"The quick 101 is that victims are tricked into copy-and-pasting a legitimate Microsoft URL into the phishing page. This URL contains an OAuth authorization code that the attacker uses to sign in to a first-party Microsoft application like Azure CLI — specifically targeting apps with known Conditional Access exclusions. ",{"data":5745,"content":5749,"nodeType":548},{"target":5746},{"sys":5747},{"id":5748,"type":553,"linkType":554},"7s4kF5CUFUmdkhpzuwNalX",[],{"data":5751,"content":5752,"nodeType":433},{},[5753],{"data":5754,"marks":5755,"value":5756,"nodeType":437},{},[],"At the end of the attack chain, the attacker is effectively granted API access to the victim's Entra account, while sidestepping MFA (even passkeys), device compliance checks, and in some cases conditional access controls (depending on the application ID targeted by the attacker). ",{"data":5758,"content":5762,"nodeType":548},{"target":5759},{"sys":5760},{"id":5761,"type":553,"linkType":554},"IMtJXMWeaIbRsWxuQ1CaS",[],{"data":5764,"content":5765,"nodeType":433},{},[5766,5770,5779],{"data":5767,"marks":5768,"value":5769,"nodeType":437},{},[],"It didn’t take long for security researchers to jump on this new technique. Lots of contributors rallied round the security recommendations (which we covered in a ",{"data":5771,"content":5773,"nodeType":456},{"uri":5772},"https://pushsecurity.com/blog/consentfix-debrief/",[5774],{"data":5775,"marks":5776,"value":5778,"nodeType":437},{},[5777],{"type":483},"follow-up blog post",{"data":5780,"marks":5781,"value":5782,"nodeType":437},{},[],") but the most notable contribution came from John Hammond, who took the attacker’s implementation and said “I can do better”. His v2 replaced a somewhat clunky implementation with a slick drag-and-drop function. But now, attackers have taken it one step further.",{"data":5784,"content":5788,"nodeType":548},{"target":5785},{"sys":5786},{"id":5787,"type":553,"linkType":554},"59tfJDRhGThKD48Wjg7uY2",[],{"data":5790,"content":5794,"nodeType":548},{"target":5791},{"sys":5792},{"id":5793,"type":553,"linkType":554},"6mEpyVD6f13ZttFmaBcxNm",[],{"data":5796,"content":5797,"nodeType":557},{},[],{"data":5799,"content":5800,"nodeType":561},{},[5801],{"data":5802,"marks":5803,"value":5805,"nodeType":437},{},[5804],{"type":510},"Introducing: ConsentFix v3",{"data":5807,"content":5808,"nodeType":433},{},[5809,5813,5822],{"data":5810,"marks":5811,"value":5812,"nodeType":437},{},[],"The latest development is that a member of the XSS criminal forum, a site strongly suspected to have ",{"data":5814,"content":5816,"nodeType":456},{"uri":5815},"https://flare.io/learn/resources/blog/state-of-the-dark-web-2026",[5817],{"data":5818,"marks":5819,"value":5821,"nodeType":437},{},[5820],{"type":483},"Russian state involvement",{"data":5823,"marks":5824,"value":5825,"nodeType":437},{},[],", has released a new tool “ConsentFix v3”, building on the v1 we saw in the wild, and John’s v2. ",{"data":5827,"content":5831,"nodeType":548},{"target":5828},{"sys":5829},{"id":5830,"type":553,"linkType":554},"4AW0UnBlIaXbIFZjy8ObY1",[],{"data":5833,"content":5837,"nodeType":548},{"target":5834},{"sys":5835},{"id":5836,"type":553,"linkType":554},"1b36XjqBpPx7wteBu6OA6h",[],{"data":5839,"content":5843,"nodeType":548},{"target":5840},{"sys":5841},{"id":5842,"type":553,"linkType":554},"4kbiWA3b096BAFGQuozPaK",[],{"data":5845,"content":5846,"nodeType":433},{},[5847,5851,5857],{"data":5848,"marks":5849,"value":5850,"nodeType":437},{},[],"It looks like broader cybercriminals are starting to take note of ConsentFix, and with the release of public tools like this one, it could be about to go mainstream — like ",{"data":5852,"content":5853,"nodeType":456},{"uri":657},[5854],{"data":5855,"marks":5856,"value":480,"nodeType":437},{},[],{"data":5858,"marks":5859,"value":5860,"nodeType":437},{},[]," has this year. ",{"data":5862,"content":5863,"nodeType":433},{},[5864],{"data":5865,"marks":5866,"value":5867,"nodeType":437},{},[],"Let’s take a closer look at some of the more interesting details of the ConsentFix v3 implementation before considering the bigger picture.  ",{"data":5869,"content":5870,"nodeType":590},{},[5871],{"data":5872,"marks":5873,"value":5875,"nodeType":437},{},[5874],{"type":510},"ConsentFix v3 under the hood",{"data":5877,"content":5878,"nodeType":433},{},[5879],{"data":5880,"marks":5881,"value":5882,"nodeType":437},{},[],"The first thing that jumps out is just how detailed this forum post is. It reads like a security vendor blog post. It walks through the key technical concepts that the reader needs to know, breaking down OAuth grants, consent phishing, refresh tokens, and FOCI (or 'Family of Client IDs' — basically, the feature that allows attackers to use a refresh token obtained for one Microsoft app to be exchanged for access tokens to other FOCI apps without re-authentication). It then walks through the history of ClickFix and ConsentFix before providing step-by-step guidance for users. ",{"data":5884,"content":5885,"nodeType":433},{},[5886],{"data":5887,"marks":5888,"value":5889,"nodeType":437},{},[],"ConsentFix v3 allows users to instrument the entire attack chain, enabling users to spin up ConsentFix infrastructure, create believable personas with which to interact with victims, craft and manage email campaigns, and automate the process of exchanging the captured OAuth token for session and refresh tokens to establish access to the compromised account. ",{"data":5891,"content":5892,"nodeType":433},{},[5893],{"data":5894,"marks":5895,"value":5896,"nodeType":437},{},[],"A combination of SaaS and open-source tools are used to perform the attack, including Cloudflare Workers for hosting, ZoomInfo for target identification, Dropbox for PDF hosting, and Pipedream as an exfiltration channel (effectively creating a webhook to automatically exchange the OAuth material in the URL for a refresh token). They also use hacker tools like SpecterPortal for post exploitation activity.",{"data":5898,"content":5899,"nodeType":557},{},[],{"data":5901,"content":5902,"nodeType":561},{},[5903],{"data":5904,"marks":5905,"value":5907,"nodeType":437},{},[5906],{"type":510},"Why attackers are turning to OAuth-based attacks",{"data":5909,"content":5910,"nodeType":433},{},[5911,5915,5922],{"data":5912,"marks":5913,"value":5914,"nodeType":437},{},[],"Attackers are increasingly turning to OAuth based techniques in 2026. Not only are “legit” OAuth connections being abused in supply chain attacks, but attacks targeting OAuth mechanisms have significantly increased with the rise of ",{"data":5916,"content":5917,"nodeType":456},{"uri":657},[5918],{"data":5919,"marks":5920,"value":480,"nodeType":437},{},[5921],{"type":483},{"data":5923,"marks":5924,"value":5925,"nodeType":437},{},[],". This is because:",{"data":5927,"content":5928,"nodeType":2377},{},[5929,5939],{"data":5930,"content":5931,"nodeType":2381},{},[5932],{"data":5933,"content":5934,"nodeType":433},{},[5935],{"data":5936,"marks":5937,"value":5938,"nodeType":437},{},[],"OAuth attacks defeat standard access controls (including passkeys)",{"data":5940,"content":5941,"nodeType":2381},{},[5942],{"data":5943,"content":5944,"nodeType":433},{},[5945],{"data":5946,"marks":5947,"value":5948,"nodeType":437},{},[],"It’s very low friction, and less likely that users will identify it as phishing (see examples below)",{"data":5950,"content":5953,"nodeType":548},{"target":5951},{"sys":5952},{"id":5787,"type":553,"linkType":554},[],{"data":5955,"content":5959,"nodeType":548},{"target":5956},{"sys":5957},{"id":5958,"type":553,"linkType":554},"2WPb41lNRajdpt5pogQg8M",[],{"data":5961,"content":5962,"nodeType":433},{},[5963],{"data":5964,"marks":5965,"value":5966,"nodeType":437},{},[],"From the user’s perspective, these aren’t situations that users are trained to treat as suspicious. In one case, the victim copies a URL (or simply drag-and-drops a box on the page). In another, they enter a short passcode that’s visible on the page. ",{"data":5968,"content":5969,"nodeType":433},{},[5970],{"data":5971,"marks":5972,"value":5973,"nodeType":437},{},[],"Both are using pop-up windows that look very convincing — and point to legitimate Microsoft pages/URLs. Even users scrutinizing the domain won’t see anything out of place. And as you can see, if the user is already signed into their Microsoft account in the browser, there’s no credential entry or MFA checks to pass through. Simply select your account from the drop down menu and … that’s it.",{"data":5975,"content":5976,"nodeType":433},{},[5977],{"data":5978,"marks":5979,"value":5980,"nodeType":437},{},[],"This unfamiliarity is the same reason that attacks like ClickFix have been so successful. In general, convincing social engineering — well crafted comms, legit-looking pages hosted on trusted sites — combined with unfamiliar payloads makes for a clever attack. And when these attacks play out entirely in the browser (circumventing endpoint controls) and sidestep identity controls, the impact is dialled up even further. ",{"data":5982,"content":5983,"nodeType":557},{},[],{"data":5985,"content":5986,"nodeType":561},{},[5987],{"data":5988,"marks":5989,"value":5991,"nodeType":437},{},[5990],{"type":510},"How ConsentFix and device code phishing overlap",{"data":5993,"content":5994,"nodeType":433},{},[5995,5999,6006],{"data":5996,"marks":5997,"value":5998,"nodeType":437},{},[],"It was only ever going to be a matter of time before ConsentFix was adopted by the mass market. But these things don’t always happen particularly fast. ",{"data":6000,"content":6001,"nodeType":456},{"uri":657},[6002],{"data":6003,"marks":6004,"value":647,"nodeType":437},{},[6005],{"type":483},{"data":6007,"marks":6008,"value":6009,"nodeType":437},{},[]," is probably the best example of this — it’s been a known technique since 2021, but it took until this year to enter mainstream adoption. A big part of that has been the availability of criminal toolkits, and also the rise in AI-assisted capabilities for tool creation (clearly at play here too). The similarity with device code phishing doesn’t end there. ",{"data":6011,"content":6012,"nodeType":433},{},[6013,6017,6026,6030,6039],{"data":6014,"marks":6015,"value":6016,"nodeType":437},{},[],"Both ConsentFix and device code phishing are OAuth attacks. They both find ways of bypassing the standard login procedure (and controls) by targeting different authorization flows, but with a similar outcome and the same advantages to an attacker. Device code phishing exploits the device authorization grant (",{"data":6018,"content":6020,"nodeType":456},{"uri":6019},"https://datatracker.ietf.org/doc/html/rfc8628",[6021],{"data":6022,"marks":6023,"value":6025,"nodeType":437},{},[6024],{"type":483},"RFC 8628",{"data":6027,"marks":6028,"value":6029,"nodeType":437},{},[],"). ConsentFix exploits the authorization code grant (",{"data":6031,"content":6033,"nodeType":456},{"uri":6032},"https://datatracker.ietf.org/doc/html/rfc6749#section-4.1",[6034],{"data":6035,"marks":6036,"value":6038,"nodeType":437},{},[6037],{"type":483},"RFC 6749",{"data":6040,"marks":6041,"value":6042,"nodeType":437},{},[],") as implemented for native/desktop apps with localhost redirects. ",{"data":6044,"content":6045,"nodeType":433},{},[6046],{"data":6047,"marks":6048,"value":6049,"nodeType":437},{},[],"The post-compromise paths are essentially identical because the tokens you get are determined by which app you target, what scopes it has, and the victim user’s permissions, not by which OAuth flow you used to obtain them. The authorization code flow and the device code flow are just different front doors into the same token issuance system.",{"data":6051,"content":6055,"nodeType":548},{"target":6052},{"sys":6053},{"id":6054,"type":553,"linkType":554},"7np3j139dWMP7sLlUQwEFC",[],{"data":6057,"content":6058,"nodeType":557},{},[],{"data":6060,"content":6061,"nodeType":561},{},[6062],{"data":6063,"marks":6064,"value":6066,"nodeType":437},{},[6065],{"type":510},"The verdict: An interesting sign of what’s coming, but maybe not the final form",{"data":6068,"content":6069,"nodeType":433},{},[6070],{"data":6071,"marks":6072,"value":6073,"nodeType":437},{},[],"It’s clear that ConsentFix v3 isn’t exactly an industrialized PhaaS-scale offering. It’s probably closer to a red team-esque proof of concept. But it is a good example of how attackers could operationalize ConsentFix campaigns using largely off-the-shelf tooling and legit SaaS tools. And an indicator of what might be coming soon. ",{"data":6075,"content":6076,"nodeType":557},{},[],{"data":6078,"content":6079,"nodeType":561},{},[6080],{"data":6081,"marks":6082,"value":5506,"nodeType":437},{},[6083],{"type":510},{"data":6085,"content":6086,"nodeType":433},{},[6087],{"data":6088,"marks":6089,"value":6090,"nodeType":437},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. We’ll talk about how we do this below, but first here’s some general recommendations. ",{"data":6092,"content":6093,"nodeType":590},{},[6094],{"data":6095,"marks":6096,"value":6098,"nodeType":437},{},[6097],{"type":510},"Microsoft ecosystem",{"data":6100,"content":6101,"nodeType":433},{},[6102,6106,6114],{"data":6103,"marks":6104,"value":6105,"nodeType":437},{},[],"Despite the similarity with device code phishing, the ",{"data":6107,"content":6108,"nodeType":456},{"uri":5530},[6109],{"data":6110,"marks":6111,"value":6113,"nodeType":437},{},[6112],{"type":483},"primary recommendation from Microsoft for device code attacks",{"data":6115,"marks":6116,"value":6117,"nodeType":437},{},[]," — disable the device code flow via conditional access — doesn’t apply to ConsentFix (because, as mentioned, it uses a different login flow).",{"data":6119,"content":6120,"nodeType":433},{},[6121,6125,6134],{"data":6122,"marks":6123,"value":6124,"nodeType":437},{},[],"For both ConsentFix and device code phishing, the ",{"data":6126,"content":6128,"nodeType":456},{"uri":6127},"https://msendpointmgr.com/2026/01/08/consentfix-quickfix/",[6129],{"data":6130,"marks":6131,"value":6133,"nodeType":437},{},[6132],{"type":483},"strongest recommendation",{"data":6135,"marks":6136,"value":6137,"nodeType":437},{},[]," is to create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them to reduce the attack surface of users that can be phished with this method.",{"data":6139,"content":6140,"nodeType":433},{},[6141],{"data":6142,"marks":6143,"value":6144,"nodeType":437},{},[],"You should also hunt in logs for relevant application IDs and resource IDs, and look for mismatches in terms of the initial access IP and subsequent activity, because while the initial login is performed by the user, subsequent actions will be performed by the attacker.  ",{"data":6146,"content":6150,"nodeType":548},{"target":6147},{"sys":6148},{"id":6149,"type":553,"linkType":554},"49Y7NXpnAeAYe9fCp1oyKn",[],{"data":6152,"content":6153,"nodeType":590},{},[6154],{"data":6155,"marks":6156,"value":6158,"nodeType":437},{},[6157],{"type":510},"Beyond Microsoft — Google, GitHub, Salesforce, AWS",{"data":6160,"content":6161,"nodeType":433},{},[6162],{"data":6163,"marks":6164,"value":6165,"nodeType":437},{},[],"It’s worth calling out that these recommendations are Microsoft specific. While in-the-wild exploitation has focused on Microsoft, GitHub, Salesforce, AWS and others are also impacted by device code phishing, supporting device code flow either as a primary or fallback mechanism (Google less so due to inherent restrictions on scopes authorized in the context of device code logins). ",{"data":6167,"content":6168,"nodeType":433},{},[6169],{"data":6170,"marks":6171,"value":6172,"nodeType":437},{},[],"Similarly, ConsentFix principles can be applied beyond Microsoft too. The core requirement is that an OAuth code ends up in a location the victim can manually see and share, e.g. a localhost redirect where no listener is present to complete the handshake. Google Cloud CLI, GitHub CLI, and others support the auth code grant and allow localhost as a redirect URI. ",{"data":6174,"content":6175,"nodeType":557},{},[],{"data":6177,"content":6178,"nodeType":561},{},[6179],{"data":6180,"marks":6181,"value":6183,"nodeType":437},{},[6182],{"type":510},"How Push can help",{"data":6185,"content":6186,"nodeType":433},{},[6187],{"data":6188,"marks":6189,"value":6190,"nodeType":437},{},[],"We’re already detecting and blocking both ConsentFix and device code phishing attacks as they target users in their web browser. When a page matches our detections for a device code or ConsentFix phishing kit (not limited to things like known-bad IPs and domains, but DOM-level analysis of the web page) Push detects and blocks it. Unlike an SWG or RBI type solution, Push analyzes every web page in every browser session and tab, in real time, with no latency. ",{"data":6192,"content":6196,"nodeType":548},{"target":6193},{"sys":6194},{"id":6195,"type":553,"linkType":554},"63EwHbmFZVAlhoXl17Xjfi",[],{"data":6198,"content":6199,"nodeType":433},{},[6200,6203,6210],{"data":6201,"marks":6202,"value":5612,"nodeType":437},{},[],{"data":6204,"content":6205,"nodeType":456},{"uri":5615},[6206],{"data":6207,"marks":6208,"value":5621,"nodeType":437},{},[6209],{"type":483},{"data":6211,"marks":6212,"value":6213,"nodeType":437},{},[]," whenever a user accesses a URL used for device code logins, across any app that supports them. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":6215,"content":6219,"nodeType":548},{"target":6216},{"sys":6217},{"id":6218,"type":553,"linkType":554},"3baS2yqvJd2e4aczw73PTF",[],{"data":6221,"content":6222,"nodeType":433},{},[6223],{"data":6224,"marks":6225,"value":6226,"nodeType":437},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing these pages if you’re confident that disruption won’t be caused. ",{"data":6228,"content":6229,"nodeType":590},{},[6230],{"data":6231,"marks":6232,"value":5646,"nodeType":437},{},[6233],{"type":510},{"data":6235,"content":6236,"nodeType":433},{},[6237],{"data":6238,"marks":6239,"value":6240,"nodeType":437},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":6242,"content":6243,"nodeType":433},{},[6244,6247,6254,6257,6264,6267,6274],{"data":6245,"marks":6246,"value":5660,"nodeType":437},{},[],{"data":6248,"content":6249,"nodeType":456},{"uri":5663},[6250],{"data":6251,"marks":6252,"value":5669,"nodeType":437},{},[6253],{"type":483},{"data":6255,"marks":6256,"value":1924,"nodeType":437},{},[],{"data":6258,"content":6259,"nodeType":456},{"uri":5675},[6260],{"data":6261,"marks":6262,"value":5681,"nodeType":437},{},[6263],{"type":483},{"data":6265,"marks":6266,"value":5685,"nodeType":437},{},[],{"data":6268,"content":6269,"nodeType":456},{"uri":5688},[6270],{"data":6271,"marks":6272,"value":5694,"nodeType":437},{},[6273],{"type":483},{"data":6275,"marks":6276,"value":1623,"nodeType":437},{},[],"ConsentFix v3: Analyzing a new criminal toolkit","Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums. ","2026-04-23T00:00:00.000Z","consentfix-v3-analyzing-a-new-toolkit",{"items":6282},[6283,6285],{"sys":6284,"name":2679},{"id":2678},{"sys":6286,"name":2683},{"id":2682},{"items":6288},[6289],{"fullName":2687,"firstName":2688,"jobTitle":2689,"profilePicture":6290},{"url":2691},"authorization-phishing","blog/authorization-phishing",{"json":6294},{"data":6295,"content":6296,"nodeType":429},{},[6297],{"data":6298,"content":6299,"nodeType":433},{},[6300],{"data":6301,"marks":6302,"value":6303,"nodeType":437},{},[],"Why attackers are pivoting to authorization-layer attacks to get around authentication controls that are resistant to traditional phishing and account takeover techniques. ","Why attackers are pivoting to authorization attacks to get around authentication controls, how they work, and what security teams can do about them.",{"id":6306,"publishedAt":6307},"1m3Hh9Gg9aHXFckcnlDi4V","2026-08-24T14:23:40.262Z",{"items":6309},[6310,6312],{"sys":6311,"name":2679},{"id":2678},{"sys":6313,"name":2683},{"id":2682},{"items":6315},[6316,6321,6326,6331,6336,6341,6344,6349],{"sys":6317,"name":6319,"slug":6320,"tier":45},{"id":6318},"topic-identity-attacks","Identity attacks","identity-attacks",{"sys":6322,"name":6324,"slug":6325,"tier":45},{"id":6323},"topic-passkeys","Passkeys","passkeys",{"sys":6327,"name":6329,"slug":6330,"tier":45},{"id":6328},"topic-mfa-bypass","MFA bypass","mfa-bypass",{"sys":6332,"name":6334,"slug":6335,"tier":45},{"id":6333},"topic-password-security","Password security","password-security",{"sys":6337,"name":6339,"slug":6340,"tier":45},{"id":6338},"topic-phaas","PhaaS","phaas",{"sys":6342,"name":647,"slug":5701,"tier":45},{"id":6343},"topic-device-code-phishing",{"sys":6345,"name":6347,"slug":6348,"tier":31},{"id":6346},"topic-phishing","Phishing","phishing",{"sys":6350,"name":6352,"slug":6353,"tier":31},{"id":6351},"topic-browser-attacks","Browser attacks","browser-attacks","4Mf0x8_bc1Kme7YgkLA9B09v09fJVSAKa61GVaqf4Vk",{"id":6356,"extension":1172,"items":6357,"meta":6753,"stem":6754,"__hash__":6755},"blogTopics/blogtopics.json",[6358,6367,6375,6384,6393,6402,6408,6417,6426,6435,6444,6453,6461,6469,6478,6484,6493,6502,6511,6519,6525,6534,6543,6552,6560,6569,6578,6584,6593,6602,6607,6613,6619,6625,6634,6642,6651,6660,6668,6676,6685,6694,6703,6711,6719,6728,6737,6745],{"sys":6359,"faqItemsCollection":6361,"name":6363,"slug":6364,"tier":31,"intro":6365,"faqTitle":59,"postCount":6366,"hasPage":19},{"id":6360},"topic-ai",{"items":6362},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":6368,"faqItemsCollection":6370,"name":6372,"slug":6373,"tier":45,"intro":6374,"faqTitle":59,"postCount":6366,"hasPage":19},{"id":6369},"topic-ai-attacks",{"items":6371},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",{"sys":6376,"faqItemsCollection":6378,"name":6380,"slug":6381,"tier":45,"intro":6382,"faqTitle":59,"postCount":6383,"hasPage":19},{"id":6377},"topic-ai-governance",{"items":6379},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":6385,"faqItemsCollection":6387,"name":6389,"slug":6390,"tier":45,"intro":6391,"faqTitle":59,"postCount":6392,"hasPage":19},{"id":6386},"topic-aitm",{"items":6388},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",77,{"sys":6394,"faqItemsCollection":6396,"name":6398,"slug":6399,"tier":45,"intro":6400,"faqTitle":59,"postCount":6401,"hasPage":6},{"id":6395},"topic-bec",{"items":6397},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",3,{"sys":6403,"faqItemsCollection":6404,"name":6352,"slug":6353,"tier":31,"intro":6406,"faqTitle":59,"postCount":6407,"hasPage":19},{"id":6351},{"items":6405},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",119,{"sys":6409,"faqItemsCollection":6411,"name":6413,"slug":6414,"tier":45,"intro":6415,"faqTitle":59,"postCount":6416,"hasPage":19},{"id":6410},"topic-browser-extensions",{"items":6412},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",30,{"sys":6418,"faqItemsCollection":6420,"name":6422,"slug":6423,"tier":31,"intro":6424,"faqTitle":59,"postCount":6425,"hasPage":19},{"id":6419},"topic-browser-security",{"items":6421},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",127,{"sys":6427,"faqItemsCollection":6429,"name":6431,"slug":6432,"tier":45,"intro":6433,"faqTitle":59,"postCount":6434,"hasPage":19},{"id":6428},"topic-casb",{"items":6430},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":6436,"faqItemsCollection":6438,"name":6440,"slug":6441,"tier":45,"intro":6442,"faqTitle":59,"postCount":6443,"hasPage":19},{"id":6437},"topic-clickfix",{"items":6439},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",39,{"sys":6445,"faqItemsCollection":6447,"name":6449,"slug":6450,"tier":45,"intro":6451,"faqTitle":59,"postCount":6452,"hasPage":19},{"id":6446},"topic-credential-phishing",{"items":6448},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",89,{"sys":6454,"faqItemsCollection":6456,"name":288,"slug":6458,"tier":45,"intro":6459,"faqTitle":59,"postCount":6460,"hasPage":19},{"id":6455},"topic-credential-stuffing",{"items":6457},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":6462,"faqItemsCollection":6464,"name":2683,"slug":6466,"tier":31,"intro":6467,"faqTitle":59,"postCount":6468,"hasPage":19},{"id":6463},"topic-detection-and-response",{"items":6465},[],"detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",101,{"sys":6470,"faqItemsCollection":6472,"name":6474,"slug":6475,"tier":45,"intro":6476,"faqTitle":59,"postCount":6477,"hasPage":19},{"id":6471},"topic-detection-engineering",{"items":6473},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",42,{"sys":6479,"faqItemsCollection":6480,"name":647,"slug":5701,"tier":45,"intro":6482,"faqTitle":59,"postCount":6483,"hasPage":19},{"id":6343},{"items":6481},[],"Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",23,{"sys":6485,"faqItemsCollection":6487,"name":6489,"slug":6490,"tier":45,"intro":6491,"faqTitle":59,"postCount":6492,"hasPage":19},{"id":6486},"topic-dlp",{"items":6488},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":6494,"faqItemsCollection":6496,"name":6498,"slug":6499,"tier":45,"intro":6500,"faqTitle":59,"postCount":6501,"hasPage":19},{"id":6495},"topic-edr",{"items":6497},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",24,{"sys":6503,"faqItemsCollection":6505,"name":6507,"slug":6508,"tier":45,"intro":6509,"faqTitle":59,"postCount":6510,"hasPage":19},{"id":6504},"topic-enterprise-browser",{"items":6506},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",6,{"sys":6512,"faqItemsCollection":6514,"name":278,"slug":6516,"tier":45,"intro":6517,"faqTitle":59,"postCount":6518,"hasPage":19},{"id":6513},"topic-ghost-logins",{"items":6515},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":6520,"faqItemsCollection":6521,"name":6319,"slug":6320,"tier":45,"intro":6523,"faqTitle":59,"postCount":6524,"hasPage":19},{"id":6318},{"items":6522},[],"Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",57,{"sys":6526,"faqItemsCollection":6528,"name":6530,"slug":6531,"tier":31,"intro":6532,"faqTitle":59,"postCount":6533,"hasPage":19},{"id":6527},"topic-identity-security",{"items":6529},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":6535,"faqItemsCollection":6537,"name":6539,"slug":6540,"tier":45,"intro":6541,"faqTitle":59,"postCount":6542,"hasPage":19},{"id":6536},"topic-infostealer",{"items":6538},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",52,{"sys":6544,"faqItemsCollection":6546,"name":6548,"slug":6549,"tier":45,"intro":6550,"faqTitle":59,"postCount":6551,"hasPage":19},{"id":6545},"topic-legitimate-service-abuse",{"items":6547},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",28,{"sys":6553,"faqItemsCollection":6555,"name":6557,"slug":6558,"tier":45,"intro":6559,"faqTitle":59,"postCount":6416,"hasPage":19},{"id":6554},"topic-malvertising",{"items":6556},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":6561,"faqItemsCollection":6563,"name":6565,"slug":6566,"tier":45,"intro":6567,"faqTitle":59,"postCount":6568,"hasPage":19},{"id":6562},"topic-malware-delivery",{"items":6564},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",13,{"sys":6570,"faqItemsCollection":6572,"name":6574,"slug":6575,"tier":45,"intro":6576,"faqTitle":59,"postCount":6577,"hasPage":19},{"id":6571},"topic-mfa",{"items":6573},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":6579,"faqItemsCollection":6580,"name":6329,"slug":6330,"tier":45,"intro":6582,"faqTitle":59,"postCount":6583,"hasPage":19},{"id":6328},{"items":6581},[],"MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",59,{"sys":6585,"faqItemsCollection":6587,"name":6589,"slug":6590,"tier":45,"intro":6591,"faqTitle":59,"postCount":6592,"hasPage":19},{"id":6586},"topic-non-email-phishing",{"items":6588},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",51,{"sys":6594,"faqItemsCollection":6596,"name":6598,"slug":6599,"tier":45,"intro":6600,"faqTitle":59,"postCount":6601,"hasPage":19},{"id":6595},"topic-oauth-abuse",{"items":6597},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":6603,"faqItemsCollection":6604,"name":6324,"slug":6325,"tier":45,"intro":6606,"faqTitle":59,"postCount":6366,"hasPage":19},{"id":6323},{"items":6605},[],"Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":6608,"faqItemsCollection":6609,"name":6334,"slug":6335,"tier":45,"intro":6611,"faqTitle":59,"postCount":6612,"hasPage":19},{"id":6333},{"items":6610},[],"Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":6614,"faqItemsCollection":6615,"name":6339,"slug":6340,"tier":45,"intro":6617,"faqTitle":59,"postCount":6618,"hasPage":19},{"id":6338},{"items":6616},[],"Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",40,{"sys":6620,"faqItemsCollection":6621,"name":6347,"slug":6348,"tier":31,"intro":6623,"faqTitle":59,"postCount":6624,"hasPage":19},{"id":6346},{"items":6622},[],"Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",92,{"sys":6626,"faqItemsCollection":6628,"name":6630,"slug":6631,"tier":45,"intro":6632,"faqTitle":59,"postCount":6633,"hasPage":19},{"id":6627},"topic-public-breach",{"items":6629},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",29,{"sys":6635,"faqItemsCollection":6637,"name":6639,"slug":6640,"tier":45,"intro":6641,"faqTitle":59,"postCount":6568,"hasPage":19},{"id":6636},"topic-ransomware",{"items":6638},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":6643,"faqItemsCollection":6645,"name":6647,"slug":6648,"tier":31,"intro":6649,"faqTitle":59,"postCount":6650,"hasPage":19},{"id":6644},"topic-saas-security",{"items":6646},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",96,{"sys":6652,"faqItemsCollection":6654,"name":6656,"slug":6657,"tier":45,"intro":6658,"faqTitle":59,"postCount":6659,"hasPage":6},{"id":6653},"topic-security-training",{"items":6655},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":6661,"faqItemsCollection":6663,"name":6665,"slug":6666,"tier":45,"intro":6667,"faqTitle":59,"postCount":6510,"hasPage":19},{"id":6662},"topic-seo-poisoning",{"items":6664},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",{"sys":6669,"faqItemsCollection":6671,"name":293,"slug":6673,"tier":45,"intro":6674,"faqTitle":59,"postCount":6675,"hasPage":19},{"id":6670},"topic-session-hijacking",{"items":6672},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",74,{"sys":6677,"faqItemsCollection":6679,"name":6681,"slug":6682,"tier":45,"intro":6683,"faqTitle":59,"postCount":6684,"hasPage":19},{"id":6678},"topic-shadow-ai",{"items":6680},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":6686,"faqItemsCollection":6688,"name":6690,"slug":6691,"tier":45,"intro":6692,"faqTitle":59,"postCount":6693,"hasPage":19},{"id":6687},"topic-shadow-saas",{"items":6689},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":6695,"faqItemsCollection":6697,"name":6699,"slug":6700,"tier":45,"intro":6701,"faqTitle":59,"postCount":6702,"hasPage":19},{"id":6696},"topic-siem",{"items":6698},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",19,{"sys":6704,"faqItemsCollection":6706,"name":6708,"slug":6709,"tier":45,"intro":6710,"faqTitle":59,"postCount":6583,"hasPage":19},{"id":6705},"topic-social-engineering",{"items":6707},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":6712,"faqItemsCollection":6714,"name":6716,"slug":6717,"tier":31,"intro":6718,"faqTitle":59,"postCount":6659,"hasPage":6},{"id":6713},"topic-supply-chain-security",{"items":6715},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":6720,"faqItemsCollection":6722,"name":6724,"slug":6725,"tier":45,"intro":6726,"faqTitle":59,"postCount":6727,"hasPage":19},{"id":6721},"topic-swg",{"items":6723},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",17,{"sys":6729,"faqItemsCollection":6731,"name":6733,"slug":6734,"tier":45,"intro":6735,"faqTitle":59,"postCount":6736,"hasPage":19},{"id":6730},"topic-third-party-risk",{"items":6732},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":6738,"faqItemsCollection":6740,"name":6742,"slug":6743,"tier":31,"intro":6744,"faqTitle":59,"postCount":6518,"hasPage":19},{"id":6739},"topic-threat-landscape",{"items":6741},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",{"sys":6746,"faqItemsCollection":6748,"name":6750,"slug":6751,"tier":45,"intro":6752,"faqTitle":59,"postCount":6492,"hasPage":19},{"id":6747},"topic-vishing",{"items":6749},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","TwtabHOH3ntGiG7tapwIFVOKFqlMpcB2zKGL3Gc9dco",1787581726030]