EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps
ID: c8ab67d0-fdb6-54f9-8c82-9483aee09cc8
STIX ID: report--c8ab67d0-fdb6-54f9-8c82-9483aee09cc8
Feed Name: cybersecurityNews.com
Threat Score
EvilTokens is a device-code phishing kit that delivers an AES-GCM encrypted phishing page which is decrypted and rendered client-side, hiding the Microsoft-branded OAuth device-code prompt from static URL analysis; the report demonstrates how browser-level sandboxing (ANY.RUN) reveals the full attack chain, associated HTTP requests, DOM changes, and IOCs to support faster triage, detection, and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
