Huntress reported a sustained 2026 wave of device code phishing that used infrastructure from BL Networks—also known as BitLaunch or BLNWX—to target Microsoft 365 users through abused authentication flows. The activity first appeared in Huntress telemetry on April 13, 2026, initially centered on IP 216.203.20[.]95, then expanded across multiple BL Networks IP ranges and remained active through late July. Researchers said the campaign relied on legitimate-looking hosting and successful device code sign-ins rather than malware delivery, allowing attackers to obtain and abuse user sessions after victims completed the authentication process.
The infrastructure overlap is notable because BL Networks has also been examined as an anonymous VPS provider attractive to criminal operators, including ransomware actors seeking harder-to-trace hosting. Huntress compared the activity to an earlier Railway-linked wave associated with the EvilTokens phishing-as-a-service platform and said the latest operations show continued adaptation rather than a wholly new technique. Defenders were urged to prioritize behavioral detection—such as unusual device code sign-ins, repeated successful logins from suspicious hosting providers, and immediate token or session revocation after suspected compromise—over campaign naming or branding.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Between July 3 and July 27, 2026, Huntress saw 26 critical-severity incidents linked to BL Networks spanning 23 identities, showing the activity was ongoing into late July.
In May 2026, Huntress observed the BL Networks-linked activity expand from a single IP address to several IPs across multiple subnets, including 193.149.176[.]151, 193.149.176[.]238, and 45.61.136[.]129.
Huntress began seeing suspicious Microsoft 365 authentication activity linked to BL Networks on April 13, 2026, marking its first observed malicious authentication activity from that provider.
Between April 13 and April 30, 2026, Huntress identified 533 events tied to BL Networks from IP address 216.203.20[.]95.
BL Networks, also known as BitLaunch or BLNWX, has been active since at least 2017 as a VPS reseller offering Linux and Windows VPS services.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.