New widespread EvilTokens kit: device code phishing as-a-service
ID: 0d911d3e-9fad-58bf-b720-68b55e49f860
STIX ID: report--0d911d3e-9fad-58bf-b720-68b55e49f860
Feed Name: Sekoia.com
Threat Score
Sekoia TDR identified EvilTokens, a turnkey Phishing-as-a-Service that delivers Microsoft device code phishing pages and backend tooling to harvest access/refresh tokens, convert refresh tokens to Primary Refresh Tokens and SSO cookies, and perform reconnaissance and post-compromise actions; the kit has been rapidly adopted by affiliates, impacted organizations globally, and is trackable via specific domain patterns, API endpoints, HTTP headers, IoCs and a YARA rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
