A phishing attack that doesn’t steal your password

Did you know that attackers can break into Microsoft accounts without stealing passwords or creating fake login pages? It’s true – a phishing kit called EvilTokens is subverting Microsoft’s authentication flow to make it happen.

Have you heard about EvilTokens, a phishing-as-a-service kit that’s causing a stir in the cybersecurity world? This kit is being used to compromise Microsoft 365 accounts by exploiting the OAuth 2.0 device authorization grant flow. What’s fascinating is that this attack method doesn’t require creating fake login pages or tricking users into giving away their passwords.

EvilTokens has been making waves since at least February 2026, with cybercriminals quickly adopting it for various nefarious purposes. From account takeovers to business email compromise attacks, this phishing kit is versatile and dangerous.

If you’re wondering how EvilTokens works, here’s a sneak peek:

  • Before launching the attack, cybercriminals conduct reconnaissance to ensure the target account is active.
  • Victims receive emails or messages disguised as invoices or shared documents, luring them to a fake page that prompts them to enter a device code from Microsoft.
  • Once the victim enters the code, thinking it’s part of a legitimate authentication process, the attacker gains access to the victim’s account without them realizing.
  • By exploiting this vulnerability, attackers can access sensitive information and prepare for further cyberattacks.

Why is EvilTokens so dangerous?

EvilTokens leverages the OAuth device code flow, originally designed for devices like smart TVs or printers. Attackers exploit this system to trick users into authorizing their devices, bypassing traditional security measures.

What’s concerning is that EvilTokens removes many typical warning signs of phishing attacks, making it harder for users to detect malicious activity. Even two-factor authentication can’t always protect against this type of attack, as users unknowingly approve the wrong session.

How can you protect yourself?

As phishing tactics evolve, it’s crucial to stay vigilant and informed. Here are some tips to reduce the risk of falling victim to attacks like EvilTokens:

  • Be cautious of unexpected requests for authentication codes and verify the legitimacy of the source before entering any sensitive information.
  • Pay attention to context and double-check the authenticity of sign-in requests, even if they appear to come from reputable sources like Microsoft.
  • Organizations should implement security measures to block unauthorized device code flows and monitor for any suspicious activity.
  • Stay alert for unusual authentication requests, unfamiliar devices, and any signs of unauthorized access to your accounts.
  • Regular security awareness training can help employees recognize and respond to modern phishing techniques effectively.
  • If you receive an unexpected authentication request, report it to your IT or security team immediately.

Remember, attackers don’t always need to steal your password to access your accounts. By staying informed and cautious, you can protect yourself against evolving cyber threats like EvilTokens.

Leave a Reply

Your email address will not be published. Required fields are marked *