29 Jul 2026
Executive summary Device code phishing turns a legitimate OAuth sign-in workflow into a remote authorization ceremony for an attacker-controlled client. The victim does not type a password into a fake page. They may never visit a look-alike Microsoft domain. Instead, the attacker starts a real OAuth 2.0 Device Authorization Grant, sends the victim its short […]
19 Jul 2026
Executive Summary APT42 continues to refine a familiar operating model, making it harder to detect and easier to scale. Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows search-ms and WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, […]
08 Jul 2026
Executive Summary The arrest and extradition of an alleged Scattered Spider member drew attention for more than the charges themselves. The most revealing detail appeared inside the court documents: Microsoft telemetry associated with a Global Device Identifier, or GDID, helped investigators connect online activity to a specific Windows installation. According to the complaint, Microsoft records […]
Discover the latest articles and insights on Dark Atlas