EvilTokens OAuth Phishing

Cloud Security Alliance (CSA) pdf 2026-05-20T00:00:00

Abstract

EvilTokens is a Phishing-as-a-Service (PhaaS) platform that weaponizes the OAuth 2.0 Device Authorization Grant to steal persistent Microsoft 365 access tokens. By redirecting the authorization output to an attacker-controlled client, the attack allows victims to complete legitimate MFA challenges on authentic Microsoft infrastructure while granting attackers long-term access. The platform further integrates LLMs to automate post-compromise email triage and Business Email Compromise (BEC) scenarios.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD