Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication

Amazon's threat intelligence team has identified and disrupted an opportunistic watering hole campaign conducted by APT29 (Midnight Blizzard), the Russian Foreign Intelligence Service (SVR)-linked threat group, Amazon disclosed on August 29, 2025.

Compromised Websites as Launchpads

APT29 compromised multiple legitimate websites and injected obfuscated JavaScript that redirected approximately 10% of visitors to actor-controlled domains. These domains — including findcloudflare[.]com — mimicked Cloudflare verification pages to appear legitimate, ultimately funneling victims into Microsoft's device code authentication flow to trick users into authorizing attacker-controlled devices.

The campaign incorporated multiple evasion techniques: randomized redirect percentages, base64-encoded malicious code, and cookie-based tracking to prevent repeated redirects of the same visitor. Amazon noted the approach demonstrates APT29's continued evolution in scaling intelligence collection operations to cast a wider net.

Persistent Despite Disruption

Upon discovery, Amazon isolated affected EC2 instances, partnered with Cloudflare and other providers to take down actor domains, and shared intelligence with Microsoft. Despite these efforts, APT29 rapidly adapted — migrating infrastructure off AWS to another cloud provider and registering new domains such as cloudflare[.]redirectpartners[.]com to continue the campaign.

Amazon noted this campaign follows a pattern: in October 2024, they disrupted APT29's use of domains impersonating AWS to phish users with RDP files, and in June 2025, Google reported APT29 phishing campaigns targeting academics and Russia critics.

ClickFix Technique Overlap

Amazon warned that some elements of the campaign matched the recently documented "ClickFix" technique, where attackers trick users into copying and pasting commands or performing actions in the Windows Run dialog (Win+R). Organizations were urged to consider disabling Microsoft's device authentication flow if not required, enforce conditional access policies, and implement robust logging for authentication events involving new device authorizations.

Read the full analysis on IntelFusions