EvilTokens: A phishing attack that doesn’t steal your password
ID: 3d87e875-d87d-56eb-b7a5-60ff632c889f
STIX ID: report--3d87e875-d87d-56eb-b7a5-60ff632c889f
Feed Name: WeLiveSecurity (ESET Research)
EvilTokens is a phishing-as-a-service kit that abuses Microsoft’s OAuth 2.0 device authorization (device-code) flow to trick users into approving attacker sessions on legitimate Microsoft login pages; attackers thereby obtain access and refresh tokens to compromise Microsoft 365 accounts for data exfiltration and business email compromise. Observed since at least February 2026 and used in campaigns (including one targeting over 340 organizations), the technique defeats password-only detection and can bypass 2FA by social engineering; recommended mitigations include disabling or scoping device-code flow, applying Conditional Access policies, monitoring for unusual token use and inbox rules, and updated security awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
