EvilTokens: A phishing attack that doesn’t steal your password

2026-06-16T08:51:36Z0168457dfa5c1a45fc8958fd45ec06efa2e363b0a844ef62000e9941c6e27bb1
account-takeovereviltokensidentity-securitymfa-bypassmicrosoftoauthopenid-connectphishingphishing-kitsingle-sign-ontoken-theft

What happened

EvilTokens is a phishing kit that subverts Microsoft’s legitimate authentication flow to achieve account takeover without stealing passwords or using fake login pages. Instead of harvesting credentials, the kit abuses the token/authorization flow (OAuth/OIDC/SSO-style interactions) to obtain or replay authentication artifacts and gain access to accounts, potentially bypassing conventional password-based defenses and some non-phishable controls. This technique raises significant risk to user accounts and organizations relying on standard federated sign‑on unless phishing‑resistant MFA, OAuth/re

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
0168457dfa5c1a45fc8958fd45ec06efa2e363b0a844ef62000e9941c6e27bb1
Enrichment time
2026-06-16T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.