A large-scale Phishing-as-a-Service campaign called EvilToken is actively compromising Microsoft 365 accounts by abusing the OAuth Device Code Authentication flow. The toolkit generates live device codes on demand, bypassing the 15-minute expiry window, and uses AI to craft role-specific phishing lures. Victims authenticate on

14m read timeFrom coralogix.com
Post cover image
Table of contents
Snowbit by Coralogix – Threat Intelligence Advisory

Sort: