Tag

#EvilTokens

1 article covering EvilTokens across campaign analysis, detection engineering, and defender tradecraft.

Coverage

1 entry

Field Analysis

Dual UseInfrastructure IntelligenceOct 6, 202610 min read

EvilTokens Goes Down: What a PhaaS Takedown Actually Buys You

Microsoft's DCU disrupted EvilTokens on September 22, 2026 — a $1,500 device-code phishing platform tied to 12,000 compromised inboxes across 10,000 organisations. The operator is gone. The flow it abused is unchanged, and the serverless infrastructure pattern is the part that outlives the brand.

Browse Other Tags

#Detection Engineering#OAuth#AiTM#Credential Theft#Identity#Supply Chain#Campaign Analysis#ClickFix#Infrastructure Intelligence#Social Engineering#MFA Bypass#Phishing Kits