EvilTokens Launches New Phishing Service Targeting Microsoft Accounts
ID: af14b373-c3ec-564e-936e-caf8c2d6a990
STIX ID: report--af14b373-c3ec-564e-936e-caf8c2d6a990
Feed Name: GBHackers
Sekoia describes EvilTokens, a commercial Phishing-as-a-Service that weaponises Microsoft OAuth device code authentication to steal access and long‑lived refresh tokens, enabling immediate and persistent access to Microsoft 365 accounts; the platform provides turnkey phishing templates, automated token conversion and reconnaissance tooling, is delivered via Telegram bots, and has been observed in broad BEC-style campaigns across multiple regions with over 1,000 hosting domains and identifiable IOCs (API paths, X-Antibot-Token header, and an AES‑GCM decryption fingerprint).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
