EvilTokens abuses real Microsoft login flows to trick users into granting attackers access to Microsoft 365 accounts.
A new phishing method is raising concern because it does not rely on fake Microsoft login pages or stolen passwords.
The campaign, known as EvilTokens, abuses Microsoft’s legitimate device code authentication flow to trick users into granting attackers access to their accounts.
In a typical attack, victims receive a message about a document, shared file or account notification. They are then asked to enter a code or confirm access through Microsoft’s genuine login process.
The issue is that the code belongs to a session started by the attacker. When the victim completes the login, they may unknowingly authorize the attacker’s access and allow them to receive valid authentication tokens.
That means even users with multi-factor authentication enabled can be affected, because the login process itself appears legitimate to the system.