EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: