⤷ Title: The Trusted Trap: How Hackers Weaponize Microsoft’s Own Login Flows to Bypass MFA
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:03:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover (ATO) #Conditional Access #Device Code Phishing #Graphish #Microsoft 365 #OAuth 2.0 #Proofpoint #SquarePhish2 #TA2723 #UNK_AcademicFlare
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:03:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover (ATO) #Conditional Access #Device Code Phishing #Graphish #Microsoft 365 #OAuth 2.0 #Proofpoint #SquarePhish2 #TA2723 #UNK_AcademicFlare
Information Security News
The Trusted Trap: How Hackers Weaponize Microsoft’s Own Login Flows to Bypass MFA
Proofpoint is warning of a surge in phishing attacks in which attackers hijack corporate Microsoft 365 accounts not through fake login pages, but via a perfectly legitimate OAuth mechanism—device …
⤷ Title: The “EvilTokens” Surge: Why Device Code Phishing Exploded 37-Fold in 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:46:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Cybersecurity 2026 #Device Code Phishing #EvilTokens #Infosec #Microsoft 365 #OAuth 2.0 #Phishing_as_a_Service #Push Security #Token Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:46:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Cybersecurity 2026 #Device Code Phishing #EvilTokens #Infosec #Microsoft 365 #OAuth 2.0 #Phishing_as_a_Service #Push Security #Token Theft
Penetration Testing Tools
The "EvilTokens" Surge: Why Device Code Phishing Exploded 37-Fold in 2026
The architecture of account exploitation is undergoing a profound metamorphosis, as adversaries increasingly eschew traditional subversion in favor
⤷ Title: New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 08:24:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Phishing #cybersecurity #Device Code Phishing #EvilToken #infosec #MFA Bypass #Microsoft Defender #Microsoft Graph #OAuth #PhaaS #Phishing_as_a_Service
Daily CyberSecurity
New AI-Driven Phishing Campaign Subverts Microsoft’s Device Code Flow
Microsoft uncovers EvilToken, an AI-powered PhaaS toolkit using Dynamic Device Code Generation to bypass MFA and breach high-value accounts. Patch now!
⤷ Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Daily CyberSecurity
AI "Vibe Coding" Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
AI "vibe coding" and the EvilTokens PhaaS platform are supercharging device code phishing to bypass Microsoft 365 MFA. Secure your network today!
⤷ Title: Device Code Phishing Using Graph Runner
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
⌗ Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
════════════════════════
𐀪 Author: Billy Andrew Amurao
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 02:07:39 GMT
════════════════════════
⌗ Tags: #phishing #account_takeover #pentesting #ethical_hacking #device_code_phishing
Medium
Device Code Phishing Using Graph Runner
1. Introduction
⤷ Title: Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 01:34:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Device Authorization Grant #Device Code Phishing #Microsoft 365 #OAuth #phishing #ReversingLabs
Daily CyberSecurity
Device Code Phishing: Microsoft 365 Attack That Steals No Passwords
A new device code phishing campaign abuses Microsoft's OAuth flow to hijack Microsoft 365 accounts, no password stealing needed. How to spot it.
⤷ Title: ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
Daily CyberSecurity
ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
At a glance Details Actor or group ARToken operators; assessed as an EvilTokens affiliate panel Activity type Phishing-as-a-service (PhaaS) with device code phishing and token theft Targets Micros…
⤷ Title: Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 07:03:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BlackFile #data extortion #Device Code Phishing #Helix #ReliaQuest #Sharepoint #ShinyHunters #Vishing
Daily CyberSecurity
Helix Data Extortion Group Emerges from BlackFile, ReliaQuest Reports
At a glance Actor / group Helix (suspected ties to BlackFile and ShinyHunters) Activity type Data extortion through identity-based intrusion Targets / victims Enterprises; high-visibility staff an…
⤷ Title: Misconfigured Server Exposes Three AiTM Phishing Operators
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:37:55 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AitM Phishing #Device Code Phishing #evilginx #LEXFO #MFA Bypass #Microsoft 365 #phishing
Daily CyberSecurity
Misconfigured Server Exposes Three AiTM Phishing Operators
At a glance Actor / group codemado, mail-argenta, saroula01 (online aliases) Activity AiTM phishing and OAuth Device Code Flow abuse Targets / victims Corporate Microsoft 365 accounts, plus crypto…
⤷ Title: Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 07:22:48 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #captive portal #Device Code Phishing #DNS Poisoning #FrostArmada #Hotel Wi_Fi #Microsoft 365 #ReliaQuest #WPAD
Daily CyberSecurity
Attackers Poison Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
At a glance Actor Unnamed operator; ReliaQuest notes tradecraft similar to APT28 (Fancy Bear, Forest Blizzard) but does not attribute the campaign Activity type Gateway compromise, DNS poisoning, …
⤷ Title: Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 06:20:59 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #Device Code Phishing #Greatness #HoneyStorm #Microsoft 365 #PhaaS #phishing
Daily CyberSecurity
Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA
At a glance Actor or group Operators of the Greatness kit, also tracked as HoneyStorm Activity type Phishing-as-a-Service with AiTM token theft and device code phishing Targets or victims Microsof…