← Back to feed
general GBHackers

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

GBHackers Microsoft

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Vi...

T1566 T1078
Read the full story GBHackers →

Related Coverage

general Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers BleepingComputer · Sep 23 general MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key The Hacker News · Sep 23 general Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster HackRead · Sep 23