← Back to feed
general GBHackers

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

GBHackers Microsoft

EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Vi...

T1566 T1078
Read the full story GBHackers →

Related Coverage

general TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution GBHackers · Aug 25 general Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions GBHackers · Aug 25