logo

AI-Powered EvilTokens Turns Hijacked Microsoft Accounts Into Financial Fraud

ID: 9fbf1cd6-e3c4-5d95-93c2-489c1a6dfce4

STIX ID: report--9fbf1cd6-e3c4-5d95-93c2-489c1a6dfce4

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Varshini

...
...

EvilTokens is a Microsoft-focused phishing-as-a-service that abuses the OAuth 2.0 device authorization flow to capture access tokens (often bypassing visible password entry and MFA), then analyzes compromised mailboxes and uses AI to craft convincing BEC and invoice-payment fraud messages; researchers linked it to a 16-day campaign impacting 344 organizations across five countries and recommend restricting device-code sign-ins and closely monitoring token issuance and unusual device or geographic logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.