EvilTokens — AI-Powered Phishing-as-a-Service Operation Drives 1,380% Surge in Microsoft 365 Device-Code Phishing
Summary Researchers have detailed “EvilTokens,” a sophisticated AI-powered phishing-as-a-service (PhaaS) operation that abuses Microsoft’s legitimate OAuth 2.0 device-code authentication flow to steal Microsoft 365 tokens at industrial scale. The operation…
