{"id":15799,"date":"2026-06-17T00:56:46","date_gmt":"2026-06-17T00:56:46","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15799"},"modified":"2026-06-17T00:56:47","modified_gmt":"2026-06-17T00:56:47","slug":"a-phishing-assault-that-doesnt-steal-your-password","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15799","title":{"rendered":"A phishing assault that doesn\u2019t steal your password"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">A phishing equipment subverting Microsoft\u2019s legit authentication move lets attackers break into accounts with out stealing passwords or creating faux login pages<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/christian-ali-bravo\/\" title=\"Christian Ali Bravo\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2023\/2023-8\/christian-ali-bravo.jpeg\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2023\/2023-8\/christian-ali-bravo.jpeg\" alt=\"Christian Ali Bravo\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>15 Jun 2026<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>5 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2026\/06-26\/eviltokens-device-token-theft.jpg\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2026\/06-26\/eviltokens-device-token-theft.jpg\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2026\/06-26\/eviltokens-device-token-theft.jpg\" alt=\"EvilTokens: A phishing attack that doesn\u2019t steal your password\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>A lot has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2023\/02\/22\/chatgpt-level-up-phishing-defenses\/\">been written<\/a> about how the times of phishing emails laden with damaged grammar and crude design are numbered, largely because of AI. In the meantime, EvilTokens provides a considerably completely different instance of how far the phishing craft has moved.<\/p>\n<p>EvilTokens is a phishing-as-a-service (PhaaS) equipment constructed to compromise Microsoft 365 accounts by abusing the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity-platform\/v2-oauth2-device-code\">OAuth 2.0 machine authorization grant move<\/a>. As assaults that use the equipment depend on machine code phishing, they sidestep the necessity for convincing replicas of real login pages the place the victims would hand over their passwords. As a substitute, attackers get the sufferer to finish a legit authentication course of \u2013 together with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2019\/12\/13\/2fa-double-down-your-security\/\">two-factor authentication<\/a> (2FA) \u2013 on an actual Microsoft login web page.<\/p>\n<p>The toolkit has been marketed by way of Telegram channels and noticed in energetic assaults since at the least February 2026. As documented by <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.sekoia.io\/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1\/\">Sekoia<\/a> and others, the equipment seems to have been rapidly adopted by cybercriminals and deployed in a variety of account takeover and <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2022\/04\/26\/trouble-bec-how-stop-costliest-scam\/\">enterprise e-mail compromise<\/a> (BEC) assaults, together with for a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2026\/03\/device-code-phishing-hits-340-microsoft.html\">marketing campaign<\/a> concentrating on greater than 340 organizations in a number of international locations in March 2026. Microsoft itself has additionally <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.theregister.com\/security\/2026\/04\/07\/hundreds-compromised-daily-in-microsoft-device-code-phishes\/5222742\">described<\/a> an AI-enabled marketing campaign that used dynamic device-code technology and bespoke lures to extend the success fee of EvilTokens assaults.<\/p>\n<h2>The internal workings of EvilTokens<\/h2>\n<p>Right here\u2019s a quick overview of how assaults leveraging EvilTokens unfold:<\/p>\n<ul>\n<li>The assault itself is preceded by \u2018reconnaissance\u2019 the place the ne\u2019er-do-wells first confirm that the goal account is energetic. Microsoft has seen this reconnaissance run 10 to fifteen days forward of the particular phishing try.<\/li>\n<li>The sufferer receives an e-mail or message that\u2019s typically dressed up as an bill, shared doc, calendar invite, or SharePoint entry request. The lure entails a decoy web page impersonating a trusted model or service, together with easy wording equivalent to \u201cConfirm to view\u201d or \u201cSignature required.\u201d<\/li>\n<li>When the sufferer clicks by means of, the web page requests a tool code from Microsoft. The code is legitimate just for quarter-hour, therefore time and timing are of the essence right here. The web page exhibits the sufferer the code alongside and factors them to Microsoft\u2019s real microsoft.com\/devicelogin login portal. The catch is that the code belongs to the attacker\u2019s session, therefore the sufferer unknowingly authorizes the attacker\u2019s machine, not their very own.<\/li>\n<li>Seeing a sound sign-in, Microsoft points entry and refresh tokens to the session opened by the attacker. As soon as inside, the criminals can entry company e-mail, recordsdata, Groups, SharePoint, OneDrive, and different Microsoft 365 sources and exfiltrate information or put together BEC assaults, which is why finance, HR, logistics, and gross sales accounts draw a lot of the attackers\u2019 curiosity.<\/li>\n<\/ul>\n<h2>What makes EvilTokens harmful<\/h2>\n<p>The OAuth machine code move was designed for gadgets that could be awkward to signal into immediately, equivalent to good TVs or printers. The machine shows a brief code that the person enters on a Microsoft web page on one other machine, typically a smartphone, and completes authentication there. Microsoft then points entry tokens to the machine that requested entry.<\/p>\n<p>That separation is beneficial, nevertheless it leaves room for abuse. Attackers can generate the code and dupe the sufferer into coming into it \u2013 all whereas Microsoft solely sees a sound authentication move. The corporate <em>does<\/em> warn customers in the mean time of sign-in by way of on-screen textual content telling them to not enter codes from sources that they don\u2019t belief. Nonetheless, a convincing decoy is typically sufficient to get the sufferer to learn previous any warnings.<\/p>\n<p>Talking of which, EvilTokens strips out most of the pink flags that folks have been <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/scams\/getting-off-hook-10-steps-take-clicking-phishing-link\/\">taught to note<\/a> over time, together with misspelled domains and pretend login pages. The login web page is actual and, from the sufferer\u2019s perspective, all the authentication course of can seem to work as anticipated.<\/p>\n<p>The assault additionally \u2018muddies the waters\u2019 in relation to safeguards offered by 2FA. Whereas the second authentication layer has by no means been extra necessary, it falls quick when the sufferer approves the improper session. In these assaults, attackers don\u2019t subvert 2FA by means of any technical wizardry \u2013 fairly, they merely dupe the sufferer into finishing 2FA for them.<\/p>\n<h2>The best way to cut back the chance<\/h2>\n<p>Phishing safety ideas clearly can\u2019t cease at \u201cexamine the hyperlink,\u201d not to mention \u201csearch for typos.\u201d These habits nonetheless assist, in fact, however they don\u2019t maintain up in opposition to fashionable assaults, particularly people who abuse actual authentication flows.<\/p>\n<p>Listed below are a number of ideas for staying protected from EvilTokens:<\/p>\n<ul>\n<li>Consider any surprising request for an authentication code as suspect. No doc, bill, e-mail, or one other platform ought to ask for a tool code with no clear cause. If the request arrives out of nowhere, flag it to your employer\u2019s IT or safety crew.<\/li>\n<li>Context issues greater than the web page. Earlier than approving any sign-in request, examine which app is asking for entry, which account is concerned, and whether or not you truly began the motion. An actual Microsoft web page doesn\u2019t mechanically make a request protected.<\/li>\n<li>Organizations ought to limit machine code move outright the place it\u2019s not wanted. Microsoft recommends making use of Conditional Entry insurance policies to dam machine code move wherever it isn\u2019t crucial and scope it to particular customers, gadgets, areas, or working programs.<\/li>\n<li>Look ahead to uncommon device-code authentication, unfamiliar gadgets, dangerous sign-ins, suspicious token use, and new inbox guidelines \u2013 any of those can level to hassle.<\/li>\n<li>Safety consciousness coaching must meet up with the newest tips up attackers\u2019 sleeves. Staff ought to perceive that fashionable phishing doesn\u2019t at all times contain typing a password right into a faux web page. Generally the attacker might ask them to enter an actual code on an actual web page \u2013 however for the improper machine.<\/li>\n<li>Staff who obtain an surprising device-code request ought to notify their firm\u2019s IT or safety groups, who might have to evaluation sign-in logs, revoke periods, invalidate refresh tokens, take away malicious inbox guidelines, and briefly disable the compromised account.<\/li>\n<\/ul>\n<p>EvilTokens is a reminder that attackers don\u2019t at all times want to interrupt the entrance door or steal the important thing to it. Generally they solely want to speak somebody into opening it.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A phishing equipment subverting Microsoft\u2019s legit authentication move lets attackers break into accounts with out stealing passwords or creating faux login pages 15 Jun 2026 \u00a0\u2022\u00a0 , 5 min. learn A lot has been written about how the times of phishing emails laden with damaged grammar and crude design are numbered, largely because of AI. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15801,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[717,1991,1631,261,1443],"class_list":["post-15799","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attack","tag-doesnt","tag-password","tag-phishing","tag-steal"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15799","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15799"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15799\/revisions"}],"predecessor-version":[{"id":15800,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15799\/revisions\/15800"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15801"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-21 08:43:45 UTC -->