#eviltokens — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #eviltokens, aggregated by home.social.
-
Cisco Talos exposes ARToken, a phishing platform using device code phishing to steal Microsoft 365 tokens and bypass MFA.
-
Cisco Talos exposes ARToken, a phishing platform using device code phishing to steal Microsoft 365 tokens and bypass MFA.
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
#ARToken #PhaaS exposes #EvilTokens' #Microsoft365 #phishing toolkit
-
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Evil Tokens pivoted to using email too.
Not surprising.The attack we observed use two nasty methods to trick victims
The email contained a (password protected) PDF
The document seemed to be blurred and presented a button "View Document". In reality this is a link
And that is the first nasty trick. It's very easy to click on this "button" without thinking. At this point you are maybe already sligtly annoyed on the hoops "security" makes you jump through 😬
After several redirects and a captcha, you end up on a fake Docusign page.
This page presents you a code and asks you to copy it. Finaly you are redirected to a real Microsoft authentication page. Entering the aforementioned code there would allow the attackers access to your Microsoft account.
I fear that the many steps and the fake security stuff reduces the mental energy available to the victim and lets them stop thinking and just following instructions.
I did a thread on the analysis of the phishing in German here
https://infosec.exchange/@realn2s/116764890301947951 -
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Und jetzt können wir auflösen.
Man kommt auf eine echte Microsoft login Seite auf der man den Code eingeben soll.
Damit ist klar, was hinter der Attacke steht. Es ist ein EvilTokens Phisching die versucht über Device Code Authentication Zugriff auf Microsoft Accounts zu erlangen.
Device Code Flow dient eigentlich dazu (IoT) Geräte die keine interaktive, lokalen Eingabemethode zur Authentifizierung haben anzubinden.Mehr zu EvilTokens unter https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/
8/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
Wow, das ist mal ein interessant gemachtes Phishing
Edit: Auflösung
Es ist eine EvilTokens Phishing Angriff der versucht euren Microsoft Account zu übernehmenAngefangen mit einer kurzen Email.
So kurz, dass sie der Empfänger*in zwar komisch vorkam aber nicht direkt gelöscht wurde.Angehängt ein Passwort-geschützes PDF. Auch wenn das Passwort in der EMail steht, wird das verhindern, dass der Inhalt des PDFs richtig geprüft werden kann.
Soweit nichts Außergewöhnliches.
Die angreifenden verwenden den korrekten Firmennamen in der EMail (nicht alle machen sich so viel Mühe 🤪)
Vielleicht fällt auf, dass der wirkliche Anhang ganz anders heißt als der "fake" Anhang im Text der Email.
1/n
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
#EvilTokens ist ein #Phishing-as-a-Service Kit, um die #0Auth #Authentifizierung von #Microsoft #Konten über die Geräteautorisierung zu unterlaufen. Hatte ich so nicht auf dem Radar - Unternehmen und deren IT sollten reagieren.
-
📢 EvilTokens : un toolkit PhaaS exploitant l'OAuth 2.0 pour du phishing de tokens à grande échelle
📝 ## 🔍 ContextePublié le 27 mai 2026 par Netcraft (auteure : Ginny Spicer), cet article présente une analyse techniqu...
📖 cyberveille : https://cyberveille.ch/posts/2026-06-01-eviltokens-un-toolkit-phaas-exploitant-l-oauth-2-0-pour-du-phishing-de-tokens-a-grande-echelle/
🌐 source : https://www.netcraft.com/blog/eviltokens-and-oauth-abuse
#EvilTokens #GhostPairing #Cyberveille -
📢 Kali365 : le FBI alerte sur une plateforme PhaaS ciblant Microsoft 365 via device code phishing
📝 ## 🔍 ContexteLe 25 mai 2026, BleepingComputer r...
📖 cyberveille : https://cyberveille.ch/posts/2026-05-28-kali365-le-fbi-alerte-sur-une-plateforme-phaas-ciblant-microsoft-365-via-device-code-phishing/
🌐 source : https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/
#Device_Code_Phishing #EvilTokens #Cyberveille -
OAuth Grants Expose Hidden Risk Below MFA Perimeter
In just five weeks, a phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organizations across five countries by exploiting a clever trick: instead of stealing passwords, it convinced users to hand over OAuth refresh tokens, granting attackers long-term access to sensitive data like mailboxes, drives, and…
#OauthSecurityRisk #Phishingasaservice #MfaBypass #Eviltokens #Microsoft365
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
📢⚠️🪝Watch out, hackers are using #CalPhishing (Calendar Phishing) with the EvilTokens phishing kit to exploit #Outlook calendar invites and device code phishing to steal #M365 session tokens and breach enterprise accounts.
Read: https://hackread.com/calphishing-eviltokens-kit-outlook-invites-m365/
-
📢 Explosion du device code phishing en 2026 : 37,5x d'augmentation et émergence du kit EvilTokens
📝 ## 🔍 ContexteArticle publié le 4 avril 2026 par Luke Jennings (VP R&D, Push Security) sur le blog pushsecurity.com.
📖 cyberveille : https://cyberveille.ch/posts/2026-09-04-explosion-du-device-code-phishing-en-2026-375x-d-augmentation-et-emergence-du-kit-eviltokens/
🌐 source : https://pushsecurity.com/blog/device-code-phishing
#DeviceCodePhishing #EvilTokens #Cyberveille -
📢 Campagne de phishing Microsoft device code à grande échelle exploitant EvilTokens pour contourner le MFA
📝 📰 **Source** : The Register — Article publié le 7 avril 2026, basé sur des déc...
📖 cyberveille : https://cyberveille.ch/posts/2026-04-11-campagne-de-phishing-microsoft-device-code-a-grande-echelle-exploitant-eviltokens-pour-contourner-le-mfa/
🌐 source : https://www.theregister.com/2026/04/07/microsoft_device_code_phishing/
#AI_powered_phishing #EvilTokens #Cyberveille -
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
TDR analysts gained access to the #EvilTokens backend JavaScript and implemented device code phishing functions and token weaponisation.
This script also includes #LLM #prompts to analyse large volumes of emails, construct BEC attack scenarios, and draft targeted #BEC emails.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Part 2 of our #EvilTokens analysis is live. TDR analysts uncovered the AI-augmented features that automate and scale #BEC workflows, marking a breakthrough in the #PhaaS ecosystem.
-
Microsoft Device-Code Phishing Attacks Compromise Hundreds Daily
A shocking reality check: a sophisticated Microsoft device-code phishing campaign, dubbed "EvilTokens," is breaching hundreds of organizations daily, using AI and automation to snoop through corporate email inboxes and steal financial data. This alarming threat is making short work of traditional security…
https://osintsights.com/microsoft-device-code-phishing-attacks-compromise-hundreds-daily
#MicrosoftDevicecodePhishing #Eviltokens #MfaBypass #AipoweredAttacks #AutomationbasedAttacks
-
Inside an AI‑enabled device code phishing campaign
#Storm_2372 #EvilTokens
https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/ -
Inside an AI‑enabled device code phishing campaign
#Storm_2372 #EvilTokens
https://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/