Device Code Phishing, Avalon Ransomware, and the NetNut Botnet Takedown
This briefing examines three significant threats to UK small and medium businesses in July 2026. First, Cisco Talos’s analysis of ARToken, a phishing-as-a-service platform exploiting Microsoft 365 device code authentication flows to bypass multi-factor authentication. The technique, productised for affiliate use, requires immediate Conditional Access policy review. Second, Blackpoint Cyber’s documentation of Avalon, a multi-stage ransomware framework using spoofed legal documents, Proton Drive hosting, and memory-only execution to evade detection. Third, the NetNut botnet takedown by Google and the FBI, involving two million compromised residential devices used as proxy infrastructure. The operational implications extend beyond the headline: unpatched IoT devices and routers continue to provide access via vulnerabilities from 2017 and 2018. Each attack is designed to appear normal within legitimate business operations. The briefing provides three concrete actions: restrict device code authentication in Entra ID, establish verification procedures for password-protected archives, and audit firmware on internet-facing devices. These measures address the gap between assumed and actual security control effectiveness in small business environments.
Chapters
IntroductionMauven introduces three threat items for 3rd July 2026, prioritised by risk to UK SMBs. Two are active attack campaigns with direct exposure, one is a law enforcement action with under-reported operational implications.
ARToken M365 Phishing PlatformAnalysis of ARToken, a phishing-as-a-service platform exploiting Microsoft device code authentication flows. The technique bypasses MFA by abusing legitimate authentication processes. Direct mitigation requires restricting device code flows through Conditional Access policies in Entra ID.
Call to ActionListener engagement prompt encouraging follows and sharing.
Avalon Ransomware FrameworkBlackpoint Cyber’s analysis of Avalon, a multi-stage attack framework using spoofed legal documents hosted on Proton Drive, password-protected ISO archives, and memory-only execution. Targets professional services with plausible social engineering. Requires staff training, behavioural endpoint detection, and ISO mounting restrictions.
The NetNut Botnet TakedownGoogle and FBI action against NetNut residential proxy botnet involving two million compromised devices. Discusses how compromised devices provide cover for credential stuffing and fraud, and notes active propagation of similar botnets via vulnerabilities from 2017 and 2018. Emphasises firmware update and credential hygiene on internet-facing devices.
Broader Pattern NoteAll three threats share a common characteristic: they are designed to appear normal within legitimate business operations. The security gap lies between assumed and actual control effectiveness, closed through visibility rather than additional tools.
OutroClosing summary with practical question for IT providers regarding Conditional Access policies. Sign-off and production credit.
Links
https://blog.talosintelligence.com/artoken-phishing-as-a-service/https://www.blackpointcyber.com/resources/blog/avalon-a-new-ransomware-framework/https://www.theregister.com/2026/07/02/google_fbi_netnut_botnet/https://www.ncsc.gov.uk/collection/device-security-guidancehttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17215https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8007