URL has been copied successfully!
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey […] The post EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/microsoft-device-codes-abuse/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link