Microsoft disrupted the EvilTokens device code phishing operation this week, confirming the technique is now industrial-scale MFA bypass. The target signs in on the real Microsoft page with real MFA,
Microsoft disrupted the EvilTokens device code phishing operation this week, confirming the technique is now industrial-scale MFA bypass. The target signs in on the real Microsoft page with real MFA, and a token gets stolen anyway. So much for 'check the URL'. This is the exact attack we run against authorized targets, and we train on that specific lure, not a yearly module. Has anyone actually se