A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.
A phishing kit called EvilTokens shows how attackers can abuse a legitimate OAuth path to collect valid Microsoft 365 tokens without stealing a password.
A Microsoft 365 phishing panel linked to the EvilTokens ecosystem shows how criminal operators are turning login abuse, token handling, and persistence into a reusable service.
A phishing-as-a-service kit tied to OAuth 2.0 shows why modern account attacks can succeed without ever stealing a password.
A new wave of phishing uses legitimate OAuth consent to turn a normal sign-in into lingering cloud access, often bypassing MFA and avoiding the look of a classic intrusion.
A phishing-as-a-service campaign built around Microsoft’s device-code sign-in flow shows why a successful MFA prompt is no longer the end of the story.
A phishing campaign tied to the EvilTokens kit is described as using Outlook invites and device-code login abuse to target Microsoft 365 sessions rather than passwords.
A new phishing-as-a-service kit is arming threat actors to hijack Microsoft accounts worldwide, targeting businesses with alarming precision.
A new Phishing-as-a-Service platform leverages Microsoft device codes and AI-powered automation to industrialize business email compromise worldwide.