Evil-Tokens Phishing

Overview

A new phishing campaign dubbed EvilTokens is exploiting Microsoft 365’s device‑login flow to compromise accounts across U.S. and European financial organizations. What makes this threat particularly dangerous is its use of “ghost” code — malicious content that remains invisible until decrypted by the browser, effectively bypassing static URL analysis and traditional SOC visibility.

How EvilTokens Works

EvilTokens hides its phishing logic behind AES‑GCM‑encrypted HTML, which only becomes readable once the browser decrypts and renders it. This means that:

  • Static URL scans see only harmless code.
  • Dynamic browser inspection reveals the real phishing flow.
  • SOC teams relying solely on network‑level detection miss the critical stage of the attack.

Once decrypted, the page mimics Microsoft’s legitimate device‑login process, tricking victims into granting access to their accounts without ever entering a password.

Why It Matters

This device‑code phishing technique allows attackers to:

  • Bypass credential capture and gain direct token‑based access.
  • Evade SOC visibility by keeping malicious code hidden until execution.
  • Delay containment and extend the window for account takeover.

The result is slower triage, incomplete evidence, and higher operational cost for security teams.

Targeted Regions and Industries

According to ANY.RUN Threat Intelligence, EvilTokens activity is clustered across the United States and Europe, with victims in:

  • Managed Security Services
  • Technology and Manufacturing
  • Education and Banking
  • Consulting and Financial Services

These sectors are especially vulnerable because a single compromised Microsoft 365 account can expose sensitive data, internal communications, and linked business services.

Closing the Visibility Gap

To detect EvilTokens effectively, SOC teams must move beyond static analysis and observe how pages behave in real time. Dynamic inspection reveals:

  • Decrypted phishing content and its execution flow.
  • Device‑code requests that link to Microsoft login APIs.
  • Infrastructure correlations connecting EvilTokens to related kits and domains.

This approach reduces manual review, speeds up containment, and provides complete evidence for blocking associated infrastructure.

Defensive Recommendations

  • Use browser‑level sandboxing to analyze dynamic content.
  • Deploy behavioral signatures for AES‑GCM decryption patterns.
  • Monitor Microsoft 365 device‑login flows for unusual token requests.
  • Educate employees on recognizing fake login prompts.
  • Integrate threat intelligence feeds to correlate EvilTokens infrastructure and IoCs.

Expert in the Cloud Insight

EvilTokens represents a new generation of phishing kits that blur the line between legitimate authentication flows and malicious code. By hiding its payload until browser execution, it creates a blind spot for traditional SOC monitoring.

For security leaders, the lesson is clear: visibility must extend to the browser layer. Dynamic analysis and behavioral inspection are no longer optional — they’re essential for detecting modern phishing kits that exploit trusted login processes.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.