EvilTokens ramps up device code phishing targeting Microsoft 365 users
2026-03-31T14:51:49Z•22f8674e9dd3496b6128ec31df0d411c364c3a332526cb62a39d074bb5b2ce0c
AxiosBitdefender','internal-attack-surface-assessment','Android-de…ClickFixEvilTokensFoxitMFA-fatigueMicrosoft-365PDF-securityRATSANS-surveyUranium-FinanceWindows-11backdoorconsolecrypto-jsdevice-code-phishingdroppersembedded-JavaScriptidentity-compromisemacOSnpmphishingsmart-contract-exploitsupply-chainterminal-warning
What happened
This feed highlights multiple active risks and defensive measures: a surge in device-code phishing against Microsoft 365 attributed to EvilTokens — a phishing toolkit offered as-a-service via Telegram that captures access/refresh tokens; a high-profile npm supply-chain compromise (trojanized crypto-js and backdoored Axios packages) that delivered droppers and remote access trojans; criminal charges in a $50M+ Uranium Finance smart-contract exploitation; and a SANS identity survey showing identity compromises and MFA fatigue. Defensive developments include Foxit’s PDF Action Inspector for JavaS
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 22f8674e9dd3496b6128ec31df0d411c364c3a332526cb62a39d074bb5b2ce0c
- Enrichment time
- 2026-03-31T14:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.