Cloud Security Alliance
EvilTokens Phishing-as-a-Service Platform Analysis
Pages
11
Time to read
17 mins
Language
English
Pages
11
Time to read
17 mins
Language
English
This technical report outlines the functionalities and implications of EvilTokens, a Phishing-as-a-Service (PhaaS) platform that exploits the OAuth 2.0 Device Authorization Grant to steal Microsoft 365 access tokens. The report details how EvilTokens operates without capturing user credentials or triggering recognizable multi-factor authentication (MFA) challenges. It describes the platform's automation capabilities using large language models for post-compromise email management and business email compromise scenario generation. The document also presents statistics on the rise of device-code phishing incidents linked to EvilTokens, highlighting a significant increase in detected phishing pages. Furthermore, it explains the structural vulnerabilities in MFA when faced with this type of attack, emphasizing that MFA does not prevent token theft but rather redirects authorization outputs to the attacker. The report concludes with a discussion on the persistence of access tokens and the potential risks posed by compromised AI agents in enterprise environments, illustrating the broader implications for organizational security.