APT29 opportunistic watering-hole device-code phishing campaign
Campaign
Summary
Hide ▲
Show ▼
APT29 is running an opportunistic watering-hole campaign that redirects visitors from compromised websites to attacker infrastructure and lures them into authorizing Microsoft device codes, increasing the risk of account takeover and intelligence collection. The operation broadened its reach by cycling infrastructure such as findcloudflare[.]com and cloudflare.redirectpartners[.]com, and it targeted visitors rather than a single named victim.
Related Happenings
GitHub fake VS Code alert spam campaign
Campaign
H score56
First: 27.03.2026 18:51
Last: 27.03.2026 18:51
Sources 1
About this happening:
A coordinated GitHub Discussions spam campaign is posting fake Visual Studio Code security alerts to lure developers into malware downloads, reaching thousands of re...
GitHub fake VS Code alert spam campaign
CampaignAbout this happening: A coordinated GitHub Discussions spam campaign is posting fake Visual Studio Code security alerts to lure developers into malware downloads, reaching thousands of re...
Ip6.arpa reverse-DNS phishing campaign using IPv6 tunneling
Campaign
H score34
First: 08.03.2026 16:12
Last: 08.03.2026 16:12
Sources 1
About this happening:
A phishing campaign is abusing ip6.arpa reverse DNS and IPv6 tunneling to slip past domain reputation checks and email security gateways, making malicious links ha...
Ip6.arpa reverse-DNS phishing campaign using IPv6 tunneling
CampaignAbout this happening: A phishing campaign is abusing ip6.arpa reverse DNS and IPv6 tunneling to slip past domain reputation checks and email security gateways, making malicious links ha...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Mic...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Mic...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
TamperedChef malvertising campaign distributing backdoor malware through trojanized PDFs
Campaign
H score37
First: 16.01.2026 14:05
Last: 16.01.2026 14:05
Sources 1
About this happening:
The TamperedChef malvertising campaign used Google ads and more than 50 domains to push a fake AppSuite PDF Editor that later activated on August 21 to steal *...
TamperedChef malvertising campaign distributing backdoor malware through trojanized PDFs
CampaignAbout this happening: The TamperedChef malvertising campaign used Google ads and more than 50 domains to push a fake AppSuite PDF Editor that later activated on August 21 to steal *...
Npm registry spear-phishing campaign targeting sales personnel
Campaign
H score28
First: 29.12.2025 11:44
Last: 29.12.2025 11:44
Sources 1
About this happening:
Unknown threat actors ran a five-month spear-phishing campaign that abused 27 npm packages as browser-hosting infrastructure, turning a software registry into a resili...
Npm registry spear-phishing campaign targeting sales personnel
CampaignAbout this happening: Unknown threat actors ran a five-month spear-phishing campaign that abused 27 npm packages as browser-hosting infrastructure, turning a software registry into a resili...
Timeline
-
29.08.2025 16:22 2 articles · 10mo ago
Amazon disrupts APT29 watering-hole campaign abusing Microsoft device code authentication
Initial DisclosureAmazon flagged and disrupted an opportunistic watering-hole campaign attributed to APT29 that used compromised websites and injected JavaScript to redirect visitors to actor-controlled domains such as findcloudflare[.]com and cloudflare.redirectpartners[.]com. The redirects mimicked Cloudflare verification pages and steered users into Microsoft device code authentication workflows designed to grant attacker-controlled access to Microsoft accounts and data.
Show sources
- Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication — thehackernews.com — 29.08.2025 16:22
- Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication — thehackernews.com — 29.08.2025 16:22