home.social

#eviltokens — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #eviltokens, aggregated by home.social.

  1. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  2. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  3. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  4. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  5. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  6. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  7. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  8. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  9. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  10. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  11. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  12. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  13. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  14. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  15. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  16. 📢 EvilTokens : un toolkit PhaaS exploitant l'OAuth 2.0 pour du phishing de tokens à grande échelle
    📝 ## 🔍 Contexte

    Publié le 27 mai 2026 par Netcraft (auteure : Ginny Spicer), cet article présente une analyse techniqu...
    📖 cyberveille : cyberveille.ch/posts/2026-06-0
    🌐 source : netcraft.com/blog/eviltokens-a
    #EvilTokens #GhostPairing #Cyberveille

  17. OAuth Grants Expose Hidden Risk Below MFA Perimeter

    In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and…

    osintsights.com/oauth-grants-e

    #OauthSecurityRisk #Phishingasaservice #MfaBypass #Eviltokens #Microsoft365

  18. 📢⚠️🪝Watch out, hackers are using (Calendar Phishing) with the EvilTokens phishing kit to exploit calendar invites and device code phishing to steal session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

  19. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  20. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  21. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  22. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  23. 📢 Explosion du device code phishing en 2026 : 37,5x d'augmentation et émergence du kit EvilTokens
    📝 ## 🔍 Contexte

    Article publié le 4 avril 2026 par Luke Jennings (VP R&D, Push Security) sur le blog pushsecurity.com.
    📖 cyberveille : cyberveille.ch/posts/2026-09-0
    🌐 source : pushsecurity.com/blog/device-c
    #DeviceCodePhishing #EvilTokens #Cyberveille

  24. 📢 Campagne de phishing Microsoft device code à grande échelle exploitant EvilTokens pour contourner le MFA
    📝 📰 **Source** : The Register — Article publié le 7 avril 2026, basé sur des déc...
    📖 cyberveille : cyberveille.ch/posts/2026-04-1
    🌐 source : theregister.com/2026/04/07/mic
    #AI_powered_phishing #EvilTokens #Cyberveille

  25. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  26. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  27. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  28. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  29. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  30. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  31. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  32. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  33. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  34. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  35. Microsoft Device-Code Phishing Attacks Compromise Hundreds Daily

    A shocking reality check: a sophisticated Microsoft device-code phishing campaign, dubbed "EvilTokens," is breaching hundreds of organizations daily, using AI and automation to snoop through corporate email inboxes and steal financial data. This alarming threat is making short work of traditional security…

    osintsights.com/microsoft-devi

    #MicrosoftDevicecodePhishing #Eviltokens #MfaBypass #AipoweredAttacks #AutomationbasedAttacks