As cited
Copy frozen at (site build).
threat intel
How EvilTokens Turbocharges Old School Phishing with AI
EvilTokens is an attack campaign that exploits legitimate device code authentication flows using AI to conduct phishing at scale against 344 organizations, bypassing the need for stolen passwords or malware. Device code phishing leverages standard OAuth and similar protocols where users are asked to visit a URL and enter a code, creating an opportunity for attackers to intercept or manipulate the flow. The campaign demonstrates how AI techniques amplify traditional phishing methods by automating targeting, personalization, or execution across large victim sets.
Why it matters: Security teams and identity administrators need to review device code authentication implementations and user training, as this attack bypasses credential-based defenses and affects any organization using OAuth, SAML, or similar federated authentication flows.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
How EvilTokens Turbocharges Old School Phishing with AI
EvilTokens uses artificial intelligence to conduct device code phishing attacks that exploit legitimate authentication flows without requiring stolen passwords or malware. The campaign targeted 344 organizations by automating traditional phishing techniques through AI.
Why it matters: Identity and access teams should understand device code flows as a phishing vector independent of credentials or malware, as this technique can bypass detection systems relying on those signals.
- Source published
- First seen by Cybersecurity Tracker