National Cyber Warfare Foundation (NCWF)

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords


0 user ratings
2026-08-25 07:02:19
milo
Red Team (CNA)

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey […]


The post EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/microsoft-device-codes-abuse/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.