EvilTokens is a phishing-as-a-service platform that sidesteps traditional defenses by hijacking account access through a legitimate Microsoft login flow—then deploys AI to automate business email compromise at scale.
Unlike credential-harvesting attacks, EvilTokens never asks victims to enter a password on a fake page. Instead, targets authenticate directly on Microsoft infrastructure while the platform silently captures OAuth tokens and converts them into a persistent, fully-operational BEC toolkit. Join Abnormal Intelligence as they break down how EvilTokens works, why it bypasses conventional controls, and what security teams can do to reduce exposure.
I OAuth Token Theft · Microsoft Login Hijack · AI-Driven BEC