<- home

Research Blog

device-code-phishingoauthmicrosoft-365mfa-bypassphishingdetection

Device-code phishing: the code that steals your account past MFA

A full walkthrough of a live Microsoft 365 device-code phishing campaign — a fake 'shared document' that never asks for your password yet still hands an attacker an MFA-approved session. Includes defanged IOCs, Entra ID hunting, and defenses.

clickfixetherhidingmalware-analysisphishingwindowsmacosdetection

Deconstructing a ClickFix variant using smart contracts for payload delivery

A full kill-chain analysis of a live ClickFix + EtherHiding campaign — a fake CAPTCHA that tricks victims into running malware hosted on the blockchain, slipping past spam filters, AV, and sandboxes. With IOCs and detection ideas.