CuraSec

Plan active

Microsoft Dismantles EvilTokens AI-Assisted Device-Code Phishing Service

2026-09-23 15:27 UTC · The Hacker News · read the source ↗ #phishing#oauth#ai-threats
  • Engineer — Plan: Device-code phishing bypasses MFA by abusing the OAuth device-authorization flow; review Conditional Access policies to restrict or block device-code grant type for untrusted networks or users who don’t need it.
  • SOC/IR — Plan: The service is dismantled but the TTP persists — build or tune detections for anomalous device-code authentication requests (unusual tenant, geolocation, or off-hours token grants) in your SIEM before copycats emerge.
  • Leader — Learn: Takedown of a 12,000-inbox-compromise phishing platform reinforces the AI-enhanced threat narrative worth including in the next leadership or board briefing on evolving phishing sophistication; no immediate exposure action required given the service is offline.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.