#eviltokens — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #eviltokens, aggregated by home.social.
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
OAuth Grants Expose Hidden Risk Below MFA Perimeter
In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and…
#OauthSecurityRisk #Phishingasaservice #MfaBypass #Eviltokens #Microsoft365
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Microsoft Device-Code Phishing Attacks Compromise Hundreds Daily
A shocking reality check: a sophisticated Microsoft device-code phishing campaign, dubbed "EvilTokens," is breaching hundreds of organizations daily, using AI and automation to snoop through corporate email inboxes and steal financial data. This alarming threat is making short work of traditional security…
https://osintsights.com/microsoft-device-code-phishing-attacks-compromise-hundreds-daily
#MicrosoftDevicecodePhishing #Eviltokens #MfaBypass #AipoweredAttacks #AutomationbasedAttacks
-
Inside an AI‑enabled device code phishing campaign
#Storm_2372 #EvilTokens
https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/ -
Inside an AI‑enabled device code phishing campaign
#Storm_2372 #EvilTokens
https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/ -
EvilTokens; new PhaaS actively targeting Microsoft 365 via Device Code Flow abuse.
The attack abuses the legitimate OAuth Device Authorization Grant. The attacker sends you a code, you enter it on the REAL microsoft.com/devicelogin page and they get your tokens. MFA bypassed. Password reset won't revoke access.
Check if the flow is used in your tenant:
Entra Sign-in logs → filter "Authentication Protocol: Device code" → Last 30 days → check all 4 tabs.
All empty? You can block safely.Block it:
Conditional Access → New policy → All users → All resources → Conditions: Authentication flows > Device code flow → Grant: Block access → ON.Takes 5 minutes. Do it now.
-
EvilTokens; new PhaaS actively targeting Microsoft 365 via Device Code Flow abuse.
The attack abuses the legitimate OAuth Device Authorization Grant. The attacker sends you a code, you enter it on the REAL microsoft.com/devicelogin page and they get your tokens. MFA bypassed. Password reset won't revoke access.
Check if the flow is used in your tenant:
Entra Sign-in logs → filter "Authentication Protocol: Device code" → Last 30 days → check all 4 tabs.
All empty? You can block safely.Block it:
Conditional Access → New policy → All users → All resources → Conditions: Authentication flows > Device code flow → Grant: Block access → ON.Takes 5 minutes. Do it now.
-
Your org should be activating Entra ID conditional access policies to outright block device code authorizations with a carveout for very limited use cases such as meeting room conferencing devices. Even Microsoft knows this and has specific guidance on how to enforce it. Device code phishing is hot right now and these device code phishing-as-a-service platforms will likely lower the barrier or entry.
https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
#phishing #eviltokens #soc #dfir #threathunting #cti #threatintel
-
Your org should be activating Entra ID conditional access policies to outright block device code authorizations with a carveout for very limited use cases such as meeting room conferencing devices. Even Microsoft knows this and has specific guidance on how to enforce it. Device code phishing is hot right now and these device code phishing-as-a-service platforms will likely lower the barrier of entry.
https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
#phishing #eviltokens #soc #dfir #threathunting #cti #threatintel
-
#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows.
⬇️
https://buff.ly/RvF5Kux -
#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows.
⬇️
https://buff.ly/RvF5Kux -
New widespread EvilTokens kit: device code phishing as-a-service – Part 1
#EvilTokens
https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/ -
New widespread EvilTokens kit: device code phishing as-a-service – Part 1
#EvilTokens
https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/ -
Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
#EvilTokens #Railway
https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign -
Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
#EvilTokens #Railway
https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign