Extended Rapid Response: Zimperium's On-Device Coverage of the EvilTokens Multi-Brand Phishing Campaign
ID: 6b5d2acc-17b3-5d08-9de4-d72f15505659
STIX ID: report--6b5d2acc-17b3-5d08-9de4-d72f15505659
Feed Name: Zimperium Blog
Research from Sekoia.io and Zimperium details "EvilTokens," a widespread Phishing-as-a-Service campaign that uses device-code OAuth phishing against Microsoft 365 to obtain persistent refresh tokens and bypass both credentials and MFA; the kit leverages trusted brand lures, disposable Cloudflare Workers infrastructure, and in-browser AES-GCM encryption to evade analysis, and Zimperium's Mobile Threat Defense can detect and block the mobile phishing URLs while researchers have published hundreds of IOCs on GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
