EvilTokens Phishing Scam Abuses Genuine Microsoft Logins

EvilTokens Phishing Scam Abuses Genuine Microsoft Logins

A new phishing method is raising concern because it does not rely on fake Microsoft login pages or stolen passwords.

The campaign, known as EvilTokens, abuses Microsoft’s legitimate device code authentication flow to trick users into granting attackers access to their accounts.

Real Login Page, Real Risk

In a typical attack, victims receive a message about a document, shared file or account notification. They are then asked to enter a code or confirm access through Microsoft’s genuine login process.

The issue is that the code belongs to a session started by the attacker. When the victim completes the login, they may unknowingly authorize the attacker’s access and allow them to receive valid authentication tokens.

That means even users with multi-factor authentication enabled can be affected, because the login process itself appears legitimate to the system.

Scroll to Top