Cybersecurity
Microsoft Takes Down EvilTokens Phishing-as-a-Service Platform

Microsoft has successfully neutralized a sophisticated phishing-as-a-service operation that specifically targeted Microsoft 365 credentials using device code flows.
Disruption of Malicious Infrastructure
Microsoft has recently conducted a major enforcement action against 'EvilTokens,' a phishing-as-a-service platform that exploited device code authentication flows. By seizing 50 websites and disabling over 150 malicious domains, Microsoft has dealt a significant blow to threat actors who were using these services to bypass traditional multi-factor authentication (MFA) protocols. This platform allowed attackers to capture authentication tokens by deceiving users into authorizing malicious devices, effectively gaining unauthorized access to corporate accounts.
Recommendations for Security Hardening
To defend against these types of sophisticated phishing attacks, organizations should adopt a zero-trust architecture. It is critical to enforce Conditional Access policies that restrict device sign-ins to known and compliant devices. Additionally, IT administrators should educate users on the risks of 'device code' phishing, encouraging them to verify the origin of any authentication requests before entering codes on unauthorized platforms. Implementing FIDO2-based hardware security keys remains the most effective defense against token-theft phishing attacks.
แหล่งที่มา: Dark Reading เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 20:02:02 GMT บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: Dark Reading
เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 20:02:02 GMT
บทความต้นฉบับ: https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
