EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
ID: de59ba1d-661e-5c63-867b-6faa77afde9a
STIX ID: report--de59ba1d-661e-5c63-867b-6faa77afde9a
Feed Name: GBHackers
EvilTokens is a phishing-as-a-service that abuses Microsoft’s Device Authorization Grant to trick victims into approving legitimate sign-ins (including MFA) that issue attacker-controlled Microsoft 365 tokens; the service, advertised since Feb 2026, combines a commercial panel/subscription model with AI-augmented post-compromise tooling to support account reconnaissance, SharePoint access, and business email compromise, and has been linked to a campaign affecting hundreds of organizations across multiple countries—defenders are advised to restrict device-code authentication, apply Conditional Access, and alert on anomalous device-code grants and mailbox/SharePoint activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
