A DNS investigation into a Microsoft 365 device code phishing campaign uncovered coordinated, disposable infrastructure, including 290 indicators of compromise, 87 malicious IP addresses and hundreds of connected domains, suggesting the operation remains active.