EvilTokens Phishing Campaign Targets Microsoft 365 Accounts Using Device Code Authentication

Since March 15, 2026, a sophisticated phishing campaign utilizing the EvilTokens toolkit has compromised hundreds of organizations daily. This campaign exploits the OAuth 2.0 device authorization grant flow, allowing att…

Free daily limit reached

Create a free account to keep reading

Unlimited cluster & entity views, full AI analysis, threat scoring, entities, sources and timelines — free, no card required.

Sign up free

Already have an account? Log in