Tuesday 14 July 2026 20:33:52 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#EvilTokens


The Phishing Page That Waited to Wake Up

Published: 08 July 2026 18:47Category: Security Awareness & Social EngineeringAuthor: PATCHKNIGHT

A ghost-phishing campaign is reportedly hiding malicious pages until they decrypt inside the browser, a trick that can leave traditional email and URL checks staring at an empty frame.

The Real Microsoft Login That Handed Criminals a Session

Published: 08 July 2026 14:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing kit called EvilTokens shows how attackers can abuse a legitimate OAuth path to collect valid Microsoft 365 tokens without stealing a password.

Affiliate Phishing Is Getting an Identity Stack of Its Own

Published: 03 July 2026 18:13Category: CybercrimeGeo: North America / USAAuthor: CRYSTALPROXY

A Microsoft 365 phishing panel linked to the EvilTokens ecosystem shows how criminal operators are turning login abuse, token handling, and persistence into a reusable service.

EvilTokens and the Quiet Theft of Trust Inside Microsoft 365

Published: 30 June 2026 15:24Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A phishing-as-a-service kit tied to OAuth 2.0 shows why modern account attacks can succeed without ever stealing a password.

The Token That Outlives the Password

Published: 21 May 2026 06:32Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A new wave of phishing uses legitimate OAuth consent to turn a normal sign-in into lingering cloud access, often bypassing MFA and avoiding the look of a classic intrusion.

The Click That Wasn’t a Password: How Consent-Based Phishing Can Outrun MFA

Published: 19 May 2026 17:08Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing-as-a-service campaign built around Microsoft’s device-code sign-in flow shows why a successful MFA prompt is no longer the end of the story.

When a Calendar Invite Becomes an Identity Trap

Published: 15 May 2026 15:00Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing campaign tied to the EvilTokens kit is described as using Outlook invites and device-code login abuse to target Microsoft 365 sessions rather than passwords.

“EvilTokens” Turns BEC into an AI-Driven Assembly Line - Microsoft 365 Under Siege

Published: 08 April 2026 15:04Category: Security Awareness & Social EngineeringAuthor: LOGICFALCON

Inside the EvilTokens Bazaar: Cybercriminals Weaponize Microsoft Device Code Phishing at Scale

Published: 02 April 2026 01:13Category: Security Awareness & Social EngineeringAuthor: CRYSTALPROXY

A new phishing-as-a-service kit is arming threat actors to hijack Microsoft accounts worldwide, targeting businesses with alarming precision.

Tokens of Deceit: How EvilTokens Is Rewriting the Microsoft Phishing Playbook

Published: 01 April 2026 04:57Category: Security Awareness & Social EngineeringAuthor: CRYSTALPROXY

A new Phishing-as-a-Service platform leverages Microsoft device codes and AI-powered automation to industrialize business email compromise worldwide.