EvilTokens: an AI-augmented phishing kit for automating BEC fraud
ID: 38d15b39-57e7-59d3-8ce8-8038175c8bf0
STIX ID: report--38d15b39-57e7-59d3-8ce8-8038175c8bf0
Feed Name: Sekoia.com
Threat Score
EvilTokens is a commercially offered Phishing‑as‑a‑Service that automates Microsoft device-code phishing to capture access/refresh tokens, weaponise them for mailbox and Graph API access, and uses an AI-driven pipeline to identify high-value payment threads and generate realistic BEC emails; the service is distributed via Telegram, includes an affiliate admin panel and webmail interface, and significantly lowers the skill and time required to conduct large-scale BEC fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
