⤷ Title: The “EvilTokens” Surge: Why Device Code Phishing Exploded 37-Fold in 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:46:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Cybersecurity 2026 #Device Code Phishing #EvilTokens #Infosec #Microsoft 365 #OAuth 2.0 #Phishing_as_a_Service #Push Security #Token Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:46:02 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Takeover #Cybersecurity 2026 #Device Code Phishing #EvilTokens #Infosec #Microsoft 365 #OAuth 2.0 #Phishing_as_a_Service #Push Security #Token Theft
Penetration Testing Tools
The "EvilTokens" Surge: Why Device Code Phishing Exploded 37-Fold in 2026
The architecture of account exploitation is undergoing a profound metamorphosis, as adversaries increasingly eschew traditional subversion in favor
⤷ Title: CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 15 May 2026 10:30:22 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Scams and Fraud #CalPhishing #Cyber Attack #Cyber Crime #Cybersecurity #EvilTokens #Fortra #M365 #Outlook #Outlook Invite #Phishing
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Fri, 15 May 2026 10:30:22 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Scams and Fraud #CalPhishing #Cyber Attack #Cyber Crime #Cybersecurity #EvilTokens #Fortra #M365 #Outlook #Outlook Invite #Phishing
Hackread
CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions
Follow us on social media at @HackRead
⤷ Title: AI “Vibe Coding” Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 06:11:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Conditional Access #Cyber Security #Device Code Phishing #EvilTokens #infosec #MFA Bypass #Microsoft 365 #PhaaS #Phishing_as_a_Service #Proofpoint #Vibe Coding
Daily CyberSecurity
AI "Vibe Coding" Fuels a Phishing Free-For-All: How EvilTokens Bypasses Microsoft 365 MFA
AI "vibe coding" and the EvilTokens PhaaS platform are supercharging device code phishing to bypass Microsoft 365 MFA. Secure your network today!
⤷ Title: How a Single KQL Query Stopped an Entire EvilTokens Phishing Campaign
════════════════════════
𐀪 Author: Matt Swann
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 21:29:58 GMT
════════════════════════
⌗ Tags: #detection_engineering #infosec #eviltokens #phishing #cybersecurity
════════════════════════
𐀪 Author: Matt Swann
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 21:29:58 GMT
════════════════════════
⌗ Tags: #detection_engineering #infosec #eviltokens #phishing #cybersecurity
Medium
How a Single KQL Query Stopped an Entire EvilTokens Phishing Campaign
Back in April of this year, an AI-powered phishing campaign known as EvilTokens took the spotlight in the infosec world. While the term…
⤷ Title: New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 17:27:27 +0000
════════════════════════
⌗ Tags: #Security #ANY RUN #Browser #Cyber Attack #Cybersecurity #EvilTokens #Microsoft 365 #Phishing #SOC #Threat Intelligence #Vulnerability
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 17:27:27 +0000
════════════════════════
⌗ Tags: #Security #ANY RUN #Browser #Cyber Attack #Cybersecurity #EvilTokens #Microsoft 365 #Phishing #SOC #Threat Intelligence #Vulnerability
Hackread
New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs
EvilTokens phishing hides takeover clues until browser execution leaving SOC teams needing deeper visibility to validate threats faster and reduce account risk.
⤷ Title: ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 08:50:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ARToken #Device Code Phishing #EvilTokens #Microsoft 365 #Phishing_as_a_Service
Daily CyberSecurity
ARToken Phishing Platform Steals Microsoft 365 Tokens and Bypasses MFA
At a glance Details Actor or group ARToken operators; assessed as an EvilTokens affiliate panel Activity type Phishing-as-a-service (PhaaS) with device code phishing and token theft Targets Micros…