New EvilTokens service fuels Microsoft device code phishing attacks
ID: ae02e319-fb3c-5182-835d-0716d72550e0
STIX ID: report--ae02e319-fb3c-5182-835d-0716d72550e0
Feed Name: Bleeping Computer
Researchers observed EvilTokens, a phishing-as-a-service kit sold on Telegram that leverages OAuth 2.0 device authorization (device code phishing) to obtain short-lived access and refresh tokens for Microsoft accounts. The service provides phishing templates (QR/hyperlink lures) tailored to finance/HR/logistics roles, automation features for business email compromise, and has been used in global campaigns; Sekoia published IoCs, YARA rules, and technical analysis to help defenders block these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
