EvilTokens OAuth Phishing
Cloud Security Alliance (CSA)
pdf
2026-05-20T00:00:00
Abstract
EvilTokens is a Phishing-as-a-Service (PhaaS) platform that weaponizes the OAuth 2.0 Device Authorization Grant to steal persistent Microsoft 365 access tokens. By redirecting the authorization output to an attacker-controlled client, the attack allows victims to complete legitimate MFA challenges on authentic Microsoft infrastructure while granting attackers long-term access. The platform further integrates LLMs to automate post-compromise email triage and Business Email Compromise (BEC) scenarios.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)