Nyxlab discloses a device code phishing kit targeting Hong Kong
The kit abuses Microsoft's device code flow to bypass MFA, captures tokens, and uses compromised mailboxes to propagate. It includes branded templates, bot detection, and a post-compromise toolkit.