home.social

#eviltokens — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #eviltokens, aggregated by home.social.

fetched live
  1. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  2. Evil Tokens pivoted to using email too.
    Not surprising.

    The attack we observed use two nasty methods to trick victims

    The email contained a (password protected) PDF

    The document seemed to be blurred and presented a button "View Document". In reality this is a link

    And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬

    After several redirects and a captcha, you end up on a fake Docusign page.

    This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.

    I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.

    I did a thread on the analysis of the phishing in German here
    infosec.exchange/@realn2s/1167

    #EvilTokens #Phishing

  3. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  4. Und jetzt können wir auflösen.

    Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.

    Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
    Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.

    Mehr zu EvilTokens unter blog.sekoia.io/new-widespread-

    8/n

    #Phishing #EvilTokens #Cybersicherheit

  5. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  6. Wow, das ist mal ein interessant gemachtes Phishing

    Edit: Auflösung
    Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmen

    Angefangen mit einer kurzen Email.
    So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.

    Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.

    Soweit nichts Außergewöhnliches.

    Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)

    Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.

    1/n

    #Cybersecurity #phishing #EvilTokens

  7. OAuth Grants Expose Hidden Risk Below MFA Perimeter

    In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and…

    osintsights.com/oauth-grants-e

    #OauthSecurityRisk #Phishingasaservice #MfaBypass #Eviltokens #Microsoft365

  8. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  9. 📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.

    Read: hackread.com/calphishing-evilt

    #CyberSecurity #CalPhishing #EvilTokens #Phishing

  10. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  11. TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.

    This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.

  12. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  13. Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.

    blog.sekoia.io/eviltokens-an-a

  14. Microsoft Device-Code Phishing Attacks Compromise Hundreds Daily

    A shocking reality check: a sophisticated Microsoft device-code phishing campaign, dubbed "EvilTokens," is breaching hundreds of organizations daily, using AI and automation to snoop through corporate email inboxes and steal financial data. This alarming threat is making short work of traditional security…

    osintsights.com/microsoft-devi

    #MicrosoftDevicecodePhishing #Eviltokens #MfaBypass #AipoweredAttacks #AutomationbasedAttacks

  15. EvilTokens; new PhaaS actively targeting Microsoft 365 via Device Code Flow abuse.

    The attack abuses the legitimate OAuth Device Authorization Grant. The attacker sends you a code, you enter it on the REAL microsoft.com/devicelogin page and they get your tokens. MFA bypassed. Password reset won't revoke access.

    Check if the flow is used in your tenant:
    Entra Sign-in logs → filter "Authentication Protocol: Device code" → Last 30 days → check all 4 tabs.
    All empty? You can block safely.

    Block it:
    Conditional Access → New policy → All users → All resources → Conditions: Authentication flows > Device code flow → Grant: Block access → ON.

    Takes 5 minutes. Do it now.

    #Microsoft365 #EntraID #CyberSecurity #EvilTokens #InfoSec

  16. EvilTokens; new PhaaS actively targeting Microsoft 365 via Device Code Flow abuse.

    The attack abuses the legitimate OAuth Device Authorization Grant. The attacker sends you a code, you enter it on the REAL microsoft.com/devicelogin page and they get your tokens. MFA bypassed. Password reset won't revoke access.

    Check if the flow is used in your tenant:
    Entra Sign-in logs → filter "Authentication Protocol: Device code" → Last 30 days → check all 4 tabs.
    All empty? You can block safely.

    Block it:
    Conditional Access → New policy → All users → All resources → Conditions: Authentication flows > Device code flow → Grant: Block access → ON.

    Takes 5 minutes. Do it now.

    #Microsoft365 #EntraID #CyberSecurity #EvilTokens #InfoSec

  17. Your org should be activating Entra ID conditional access policies to outright block device code authorizations with a carveout for very limited use cases such as meeting room conferencing devices. Even Microsoft knows this and has specific guidance on how to enforce it. Device code phishing is hot right now and these device code phishing-as-a-service platforms will likely lower the barrier or entry.

    blog.sekoia.io/new-widespread-

    learn.microsoft.com/en-us/entr

    #phishing #eviltokens #soc #dfir #threathunting #cti #threatintel

  18. Your org should be activating Entra ID conditional access policies to outright block device code authorizations with a carveout for very limited use cases such as meeting room conferencing devices. Even Microsoft knows this and has specific guidance on how to enforce it. Device code phishing is hot right now and these device code phishing-as-a-service platforms will likely lower the barrier of entry.

    blog.sekoia.io/new-widespread-

    learn.microsoft.com/en-us/entr

    #phishing #eviltokens #soc #dfir #threathunting #cti #threatintel

  19. #TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows.
    ⬇️
    buff.ly/RvF5Kux

  20. #TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows.
    ⬇️
    buff.ly/RvF5Kux