Microsoft disrupted the EvilTokens device code phishing operation this week, confirming the technique is now industrial-scale MFA bypass. The target signs in on the real Microsoft page with real MFA,

Microsoft disrupted the EvilTokens device code phishing operation this week, confirming the technique is now industrial-scale MFA bypass. The target signs in on the real Microsoft page with real MFA, and a token gets stolen anyway. So much for 'check the URL'. This is the exact attack we run against authorized targets, and we train on that specific lure, not a yearly module. Has anyone actually se

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Microsoft disrupted the EvilTokens device code phishing operation this week, confirming the technique is now industrial-scale MFA bypass. The target signs in on the real Microsoft page with real MFA,

mastodon:infosec-exchangeother4d ago kagi ↗

Microsoft disrupted the EvilTokens device code phishing operation this week, confirming the technique is now industrial-scale MFA bypass. The target signs in on the real Microsoft page with real MFA, and a token gets stolen anyway. So much for 'check the URL'. This is the exact attack we run against authorized targets, and we train on that specific lure, not a yearly module. Has anyone actually se