home.social

#eviltokens — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #eviltokens, aggregated by home.social.

fetched live
  1. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  2. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  3. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  4. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  5. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  6. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  7. EvilTokens; new PhaaS actively targeting Microsoft 365 via Device Code Flow abuse.

    The attack abuses the legitimate OAuth Device Authorization Grant. The attacker sends you a code, you enter it on the REAL microsoft.com/devicelogin page and they get your tokens. MFA bypassed. Password reset won't revoke access.

    Check if the flow is used in your tenant:
    Entra Sign-in logs → filter "Authentication Protocol: Device code" → Last 30 days → check all 4 tabs.
    All empty? You can block safely.

    Block it:
    Conditional Access → New policy → All users → All resources → Conditions: Authentication flows > Device code flow → Grant: Block access → ON.

    Takes 5 minutes. Do it now.

    #Microsoft365 #EntraID #CyberSecurity #EvilTokens #InfoSec

  8. Your org should be activating Entra ID conditional access policies to outright block device code authorizations with a carveout for very limited use cases such as meeting room conferencing devices. Even Microsoft knows this and has specific guidance on how to enforce it. Device code phishing is hot right now and these device code phishing-as-a-service platforms will likely lower the barrier or entry.

    blog.sekoia.io/new-widespread-

    learn.microsoft.com/en-us/entr

    #phishing #eviltokens #soc #dfir #threathunting #cti #threatintel

  9. #TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows.
    ⬇️
    buff.ly/RvF5Kux