TI Mindmap HUB
Threat Intelligence Report

Unmasking EvilTokens: Getting to the root of device code phishing

๐Ÿ“… September 22, 2026 ๐Ÿ“ฐ www.microsoft.com ๐Ÿ” 0 CVE(s) referenced

Microsoft disrupted EvilTokens, an AI-powered phishing-as-a-service platform that abused OAuth device code authentication to steal tokens, evade MFA, and enable business email compromise across more than 12,000 inboxes in 10,000 organizations worldwide.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle