news.mlab.sh
Back to the feed
threat-intel

EvilTokens: A phishing attack that doesn’t steal your password

High
Summary

EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking legitimate requests like invoices or SharePoint access – to trick users into providing device codes, which then grant access to their Microsoft 365 accounts. The kit has been actively deployed since February 2026, targeting over 340 organizations globally, and is particularly effective against 2FA, as it simply requires users to approve a code for a device they didn't initiate. Organizations should restrict device code flow and bolster security awareness training to combat this evolving threat.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.