DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
DEBULL is a reusable tooling layer that packages Storm-2372-style identity tradecraft into a PhaaS platform. It provides campaign-facing and operator-facing infrastructure, using…
GraphSpy is a tool used for post-exploitation of Microsoft 365 and Entra environments, often integrated into PhaaS platforms like DEBULL. It enables…