Researchers detail device-code OAuth abuse behind the scheme
2 Sep 22 · 1d ago · 6 articles · 2 posts · 3 sources · development 2 of 2
Microsoft and security firm SpyCloud described how EvilTokens automated spam emails that led victims to pages running hidden scripts to generate device authentication codes via Microsoft Entra, letting attackers enroll their own devices and evade signature-based detection.
“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed.”
Microsoft, Company statement · mastodon ↗Microsoft Investigating companySpyCloud Security firmUK Metropolitan Police Service Law enforcementDan Goodin Ars Technica security reporter
The whole story articlesposts the bright band is this development · numbered dots are the others · click one to jump
Reported in the same hours no headline names this development itself — these 4 claims were published in its stretch
-
2 outlets Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
first by The Hacker News, 1d ago · also Dark Reading
1 more headline
- Microsoft Disrupts EvilTokens Device Code Phishing Service Dark Reading · 1d ago
-
first by Mastodon, 1d ago · also Ars Technica
1 more headline
- Microsoft disrupts AI-assisted platform that compromised 12,000 Ars Technica · 1d ago
-
first by BleepingComputer, 1d ago
-
first by csoonline.com, 1d ago
What people said 1 voice · verbatim
-
R
#Discover #Security #Privacy #Microsoft #AI #DataCenters #Platform #CompromisedAccounts #Cybersecurity #Tech #TechNews
All 2 developments of Microsoft dismantles EvilTokens, an AI-driven phishing… →
MastodonNewswiresGoogle NewsHacker NewsBluesky