CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

How EvilTokens Turbocharges Old School Phishing with AI

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 697

As cited

Copy frozen at (site build).

threat intel

How EvilTokens Turbocharges Old School Phishing with AI

EvilTokens is an attack campaign that exploits legitimate device code authentication flows using AI to conduct phishing at scale against 344 organizations, bypassing the need for stolen passwords or malware. Device code phishing leverages standard OAuth and similar protocols where users are asked to visit a URL and enter a code, creating an opportunity for attackers to intercept or manipulate the flow. The campaign demonstrates how AI techniques amplify traditional phishing methods by automating targeting, personalization, or execution across large victim sets.

Why it matters: Security teams and identity administrators need to review device code authentication implementations and user training, as this attack bypasses credential-based defenses and affects any organization using OAuth, SAML, or similar federated authentication flows.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

How EvilTokens Turbocharges Old School Phishing with AI

EvilTokens uses artificial intelligence to conduct device code phishing attacks that exploit legitimate authentication flows without requiring stolen passwords or malware. The campaign targeted 344 organizations by automating traditional phishing techniques through AI.

Why it matters: Identity and access teams should understand device code flows as a phishing vector independent of credentials or malware, as this technique can bypass detection systems relying on those signals.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary