Plan
active
Microsoft Dismantles EvilTokens AI-Assisted Device-Code Phishing Service
- Engineer — Plan: Device-code phishing bypasses MFA by abusing the OAuth device-authorization flow; review Conditional Access policies to restrict or block device-code grant type for untrusted networks or users who don’t need it.
- SOC/IR — Plan: The service is dismantled but the TTP persists — build or tune detections for anomalous device-code authentication requests (unusual tenant, geolocation, or off-hours token grants) in your SIEM before copycats emerge.
- Leader — Learn: Takedown of a 12,000-inbox-compromise phishing platform reinforces the AI-enhanced threat narrative worth including in the next leadership or board briefing on evolving phishing sophistication; no immediate exposure action required given the service is offline.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.