EvilTokens ramps up device code phishing targeting Microsoft 365 users
ID: d488cf4e-05d2-58e3-9037-fd115973ac62
STIX ID: report--d488cf4e-05d2-58e3-9037-fd115973ac62
Feed Name: Help Net Security
Security researchers report a notable increase in device-code phishing against Microsoft 365 driven by EvilTokens, a Telegram-distributed phishing-as-a-service that automates lure creation, Microsoft API interactions, and harvesting of access/refresh tokens (and potentially PRTs) to bypass MFA and maintain persistent account access; the kit includes ready-made templates targeting finance, HR and logistics and provides post-compromise triage features, and defenders are advised to train users, restrict device code authentication via Conditional Access, monitor anomalous sign-ins, and revoke suspected refresh tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
