DEBULL: Phishing-as-a-Service Platform for Device Code Attacks
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
EvilTokens is a phishing kit released in February 2026 that significantly lowered the barrier to entry for device code phishing. Its availability…
Tycoon 2FA is a phishing kit that has been observed in campaigns combining its tradecraft with OAuth device code authorization flows. Despite…
LevelBlue advises blocking the device code authentication method globally in Conditional Access Policies to prevent device code phishing. If the flow is…
Trend Micro published an analysis of device code phishing, describing it as the next step after AiTM phishing. The analysis notes that…
ShinyHunters is a threat actor known for large-scale data breaches. In 2025, they used device code phishing against Salesforce tenants, compromising over…
Salesforce has been targeted by nation-state actors and criminal groups using device code phishing. The ShinyHunters campaign compromised over 1,000 organizations, demonstrating…