
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey […]
The post EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.