Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
EvilTokens AI Targets Microsoft 365 Users for Phishing

EvilTokens AI Targets Microsoft 365 Users for Phishing

Posted on August 25, 2026 By CWS

EvilTokens is transforming phishing attacks by leveraging AI to exploit Microsoft 365 session access. This advanced service goes beyond the typical phishing scenario, not only capturing session tokens but also analyzing the compromised mailbox to identify potential targets for fraud.

Advanced Phishing Techniques

Unlike traditional credential theft methods, EvilTokens employs a genuine Microsoft login process. Victims are lured to a controlled webpage where a device code is generated, leading them to Microsoft’s legitimate login site to authorize access.

This approach, known as OAuth device code phishing, ensures victims end up on an authentic page, not a counterfeit one, making detection difficult.

Scope and Impact

First documented in February 2026, EvilTokens primarily markets its services via Telegram. The service’s combination of session capture and post-compromise analysis is appealing even to those with minimal financial fraud expertise.

A recent 16-day assault affected 344 organizations across five countries. Additional research uncovered over 1,000 infrastructure-related search results and 66 email attachments linked to EvilTokens, indicating its rapid transition from promotion to active use.

Phishing Strategy and AI Role

The unique aspect of EvilTokens lies in its post-theft operations. Once access is gained, it scours emails for financial documents, identifying key individuals involved in payment approvals and mapping organizational communication styles.

This data enables attackers to craft convincing follow-up scams. The AI-driven platform analyzes email content to generate messages that reflect actual business interactions, allowing attackers to target known contacts with precision.

Security Implications and Recommendations

EvilTokens’ methods highlight the growing threat of device-code phishing. Organizations should restrict device-code authentication to essential situations and monitor unexpected approvals, new token issuances, and unusual account activities.

Security teams must remain vigilant beyond initial detections, looking for signs of mailbox manipulation, unauthorized cloud data access, and user impersonation.

Encouraging staff to question unexpected login prompts and approval requests can also help mitigate potential threats. Awareness of past EvilTokens campaigns underscores the importance of skepticism, even when faced with familiar branding.

Conclusion

EvilTokens exemplifies the evolution of phishing tactics, combining session access with strategic AI analysis to enhance the effectiveness of cyberattacks. As these threats grow more sophisticated, organizations must adapt their defenses and educate their workforce to prevent breaches and protect sensitive information.

Cyber Security News Tags:AI attacks, cyber threats, Cybercrime, Cybersecurity, device code phishing, email compromise, EvilTokens, fraud prevention, Microsoft 365, OAuth, Phishing, security measures, session hijacking, SOC, threat intelligence

Post navigation

Previous Post: WhatsApp Enhances Security with New Passkeys and 2SV
Next Post: WhatsApp Enhances Security with New Passkey Features

Related Posts

Detecting Ransomware with Windows Minifilter Technology Detecting Ransomware with Windows Minifilter Technology Cyber Security News
Massive FortiBleed Attack Breaches 430,000+ Firewalls Massive FortiBleed Attack Breaches 430,000+ Firewalls Cyber Security News
GhostRedirector Hackers Compromise Windows Servers With Malicious IIS Module To Manipulate Search Results GhostRedirector Hackers Compromise Windows Servers With Malicious IIS Module To Manipulate Search Results Cyber Security News
Thousands of Fortinet Firewalls Targeted in Global Cyber Attack Thousands of Fortinet Firewalls Targeted in Global Cyber Attack Cyber Security News
Germany Urges Apple, Google to Block Chinese AI App DeepSeek Over Privacy Rules Germany Urges Apple, Google to Block Chinese AI App DeepSeek Over Privacy Rules Cyber Security News
NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools NETREAPER Offensive Security Toolkit That Wraps 70+ Penetration Testing Tools Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism
  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure
  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New SLEEPWALKER Backdoor Uses Unique Trigger Mechanism
  • Iran-Linked Cyber Group Intensifies Attacks with New Methods
  • AI Accelerates Malware Creation, But Not Its Effectiveness
  • CISA Red Team Exposes Security Gaps in Key Infrastructure
  • OpenAI Blocks Russia-Linked ChatGPT Accounts Over Influence Campaign

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark