How EvilTokens Turbocharges Old School Phishing with AI

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

EvilTokens is an AI-powered phishing-as-a-service (PhaaS) platform that weaponized device code phishing to compromise 344 organizations across five countries over 16 days. The attack exploits a legitimate OAuth authentication flow — no stolen passwords or malware required — by tricking users into handing over valid session tokens. AI was integrated throughout the attack chain: generating personalized lures, dynamically creating device codes, and automatically drafting follow-on wire fraud emails in the victim's own voice within minutes of token capture. Traditional email security controls (Cisco, Trend Micro, Mimecast) failed to detect it because the infrastructure and authentication flows were entirely legitimate. Defenders are advised to enforce contextual conditional access policies, monitor for new device registrations, adopt phishing-resistant MFA (FIDO2/passkeys), and shift to behavior-based detection rather than relying on more alerts.

7m read timeFrom huntress.com
Post cover image
Table of contents
How the EvilTokens device code phishing campaign was spottedEvilTokens is a phishing-as-a-service platform. Here’s what that means.How AI made EvilTokens faster, smarter, and harder to detectWhy traditional email defenses failed against device code phishingThe phishing-as-a-service ecosystem behind EvilTokensHow to defend against device code phishing and MFA bypass attacks