Tokens is a new phishing kit that allows attackers to gain access to corporate accounts, even when they have multi-factor authentication (MFA), by operating covertly through legitimate Microsoft services.
EvilTokens is a new phishing kit that allows attackers to gain access to corporate accounts, even when they have multi-factor authentication (MFA), by operating covertly through legitimate Microsoft services.
The cybersecurity company ESET has warned about EvilTokens, a ‘phishing’ kit as a service (PhaaS), which aims to compromise Microsoft 365 accounts through a system of deception through a legitimate authentication mechanism.
LOOK: How a hidden message in a lawsuit tried to deceive an AI in a Brazilian court
This ‘cybercrime as a service’ approach is already being used in advanced campaigns in which other types of approaches are used in attacks executed by Artificial Intelligence (AI), as happened when a single cybercriminal hacked 9 government agencies.
ESET Spain’s director of research and awareness, Josep Albors, says that “for years we have taught users to be wary of suspicious links or fake login pages, but attacks like EvilTokens show that criminals are adapting their tactics.”
The EvilTokens kit bases its ploy on an attack style that uses device codes that allow attackers to gain access to corporate accounts.
`; document.body.appendChild(modalWrapper); let figcaption = modalWrapper.querySelector(“figcaption”); if(figcaption) figcaption.style.display=”none”; modalWrapper.querySelector(“.s-multimedia__close-modal”).addEventListener(“click”,()=>{modalWrapper.remove(); e.style.display=”flex”; if(caption) caption.style.display=”block”;});})})});});
These accounts are not even saved from this type of attack when they use multi-factor authentication, a system that has served as an insurmountable barrier for many of the cyber attacks that organizations often suffer.
“In this case, the victim interacts with a legitimate Microsoft page and completes a real authentication process, which makes the fraud much more difficult to detect,” says Albors to show the danger of this type of technique that appears as legitimate access when access is actually being authorized to a cybercriminal.
This new ploy, as explained by ESET, begins when attackers generate a valid device code and is incorporated into all those components and daily actions of any employee such as an email, an invoice and even access requests to corporate platforms.
The hook to break down the resistance that an employee might have in the face of a ‘phishing’ attack occurs when he or she is directed to a legitimate Microsoft page, where he or she ends up entering said code and ends up completing the authentication process.
Here, Albors warns that “this type of access can later be used for information theft, data exfiltration or launching corporate email compromise (BEC) attacks, especially against finance, human resources, logistics or sales departments.”
That EvilTokens is able to deceive the potential victim in this way is due to the fact that it uses the OAuth 2.0 device authorization flow, which is characterized by the convenience it offers to log in to devices such as Smart TVs or connected printers.
LOOK: World Cup 2026: the trends that mark the way of experiencing football on TikTok
With this type of ‘phishing’ attack, organizations face two serious problems. The first is that many of the indicators with which it can be identified that the victim is facing an attack of this nature are eliminated.
The second has to do with the recommendations, since they put the user in a state of alarm who will have to take more drastic and proactive measures to avoid falling into these new, more complex tricks.
These range, according to ESET, from being wary of any unexpected request to enter an authentication code to verifying which application is requesting permissions before an access approval, as well as not assuming that a request is secure just because it only occurs on a legitimate page.
Other recommendations are to inform the IT department of any code requests, stay alert for unusual startup notifications, and, if managing enterprise security, limit the use of device code flows when they are not strictly necessary.
https://www.willoughbypark.co.uk/post/winter-regional-bd-results-31-january?commentId=1fad6a33-43c0-444a-869d-f8a3c67901f7
https://www.sharewise.com/us/forums/12/forum_threads/49341?comment_id=545579&page=1#comment-545579
https://www.beinginvincible.org/group/astronomy/discussion/e7cc7693-048a-4a45-a7e4-5764e07694dd?commentId=b107bbcf-c126-4d60-808a-290bc099b18f
https://pbase.com/yonda/online_gamez
https://codeberg.org/yonda/onlineplatforms/issues/2#issue-5845475
https://www.rmitrainingacademy.co.uk/single-post/what-s-on-at-the-rmi-academies-october-2021?commentId=ce4fba0c-c8a2-4ee8-adf6-9dabe8c4333f
https://www.jobcase.com/conversations/57ffac41-f04e-4e23-9eb5-3c43e0e0c849
https://vethelpdirect.com/ask-a-vet/topic/premium-pet-products-for-dogs-cats-shop-smarter-online/#post-49013
https://www.thecircleindia.org/group/the-circle-group-1/discussion/849c6ffb-588f-49dd-9c38-b4748bdc3804?commentId=a1bc7a39-d164-4927-8c61-bba6ff76f48b
https://rawg.io/collections/online-games-12
https://www.hampshireswifts.co.uk/post/cala-homes-the-kings-barton-development-and-the-case-of-the-missing-swift-bricks?commentId=e33ef2ca-4818-4be1-8106-f09e30bf6251
https://www.hindutemplemn.org/group/hsmn-group/discussion/e66eda93-c626-4934-8a2c-0b6f660315f9?commentId=29ebfdf9-58f3-4155-ab3f-3e8df48770a3
https://mforum.cari.com.my/home.php?mod=space&uid=3394231&do=blog&quickforward=1&id=612932
https://blankslate.io?note=1318658
https://telegra.ph/Casino-06-16-3
https://www.northwestjewelleryschool.co.uk/post/the-value-of-scrap-silver-from-waste-to-workshops?commentId=4762a7ea-caaf-4f95-ac08-ebef43142fbc
https://remlr.com/forum/index.php?topic=7175.0
https://www.monetwork.org/group-page/monetwork-group/discussion/e9ffec17-494b-472e-9d4b-a669e210bdeb?commentId=fc29d18b-f352-4d31-942a-1a57b53b8598
https://sites.google.com/view/blakez/главная-страница
https://medium.com/@dartvaider127/online-platform-5be3882de4c8
https://www.tumblr.com/sportsresultsandrecovery/819581198298939392/online-game?source=share
https://www.lewistaxis.co.uk/post/private-taxi-hire-vs-public-transport-best-commute-choice?commentId=3213028c-36fb-4006-a0a5-a2f088fdea50
https://magic.ly/Horik/Online-platform
https://dev.to/funk435/online-game-4146
https://openlibrary.org/people/alex_ostin/lists/OL338107L/Online_game