logo

Extended Rapid Response: Zimperium's On-Device Coverage of the EvilTokens Multi-Brand Phishing Campaign

ID: 6b5d2acc-17b3-5d08-9de4-d72f15505659

STIX ID: report--6b5d2acc-17b3-5d08-9de4-d72f15505659

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

...
...

Research from Sekoia.io and Zimperium details "EvilTokens," a widespread Phishing-as-a-Service campaign that uses device-code OAuth phishing against Microsoft 365 to obtain persistent refresh tokens and bypass both credentials and MFA; the kit leverages trusted brand lures, disposable Cloudflare Workers infrastructure, and in-browser AES-GCM encryption to evade analysis, and Zimperium's Mobile Threat Defense can detect and block the mobile phishing URLs while researchers have published hundreds of IOCs on GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.