How EvilTokens Turbocharges Old School Phishing with AI
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
EvilTokens is an AI-powered phishing-as-a-service (PhaaS) platform that weaponized device code phishing to compromise 344 organizations across five countries over 16 days. The attack exploits a legitimate OAuth authentication flow — no stolen passwords or malware required — by tricking users into handing over valid session tokens. AI was integrated throughout the attack chain: generating personalized lures, dynamically creating device codes, and automatically drafting follow-on wire fraud emails in the victim's own voice within minutes of token capture. Traditional email security controls (Cisco, Trend Micro, Mimecast) failed to detect it because the infrastructure and authentication flows were entirely legitimate. Defenders are advised to enforce contextual conditional access policies, monitor for new device registrations, adopt phishing-resistant MFA (FIDO2/passkeys), and shift to behavior-based detection rather than relying on more alerts.