EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog .
Unmasking EvilTokens: Getting to the root of device code phishing
calendar_today
September 22, 2026
person
Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research
domain
microsoft-defender