By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Cybersecurity Beat
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • Resources
  • About
    • Mission
    • Services
    • Contact
Reading: New PhishingKit Exploits Browser Side Decryption to Hide Microsoft 365 Account Takeover
  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
Cybersecurity BeatCybersecurity Beat
Font ResizerAa
Search
  • News & Alerts
  • Articles
  • Spotlight
  • Features
  • Resources
Follow US
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

New PhishingKit Exploits Browser Side Decryption to Hide Microsoft 365 Account Takeover

The EvilTokens phishing kit encrypts its landing page content with AES GCM to bypass static URL analysis, exploiting Microsoft's device code login process for account takeover.

CSBadmin
Last updated: June 30, 2026 6:15 am
CSBadmin
2 Min Read
Share
SHARE

How the Attack Works

A sophisticated phishing kit known as EvilTokens is targeting organizations across the United States and Europe, using a technique that hides its malicious activity from traditional security tools. The attack exploits Microsoft’s legitimate device code authentication flow, tricking victims into granting access to their own Microsoft 365 accounts without the attackers ever capturing passwords directly.

Contents
How the Attack WorksImpact and Scope

The kit’s effectiveness stems from its use of encrypted landing page HTML. The page content is encrypted using AES GCM and only becomes readable within the victim’s browser after decryption occurs. This means static URL analysis and network level detection tools often miss the actual phishing content, recording only an encrypted response while never revealing what the victim sees on screen.

Impact and Scope

Security researchers have identified EvilTokens activity concentrated primarily across the United States and Europe, targeting sectors including managed security services, technology, manufacturing, education, banking, and consulting. The kit focuses on environments where a single compromised Microsoft 365 account provides access to sensitive data, internal communications, and linked business services.

The encrypted approach creates significant challenges for security operations teams. When analysts cannot observe what a suspicious page does after execution in the browser, the consequences include longer exposure to potential account compromise, delayed containment decisions, increased alert volumes for senior staff, higher investigation costs, and incomplete evidence for blocking related infrastructure. Security teams need browser level analysis capabilities to detect the decrypted phishing content and confirm threats rapidly.

Source: Cyber Security News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverEvilTokens
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Water Utilities Targeted Through Weak PLC Security and Exposed Controls
Next Article Conditional Access Bypass Exploits Microsoft Entra Nested App Flow

Trending

Nissan Employee Data Exposed in Oracle PeopleSoft Zero-Day Attack
June 30, 2026
C++ Rewrite Fuels Global Surge in Millenium RAT Infections
June 30, 2026
Google Patches Critical Sandbox Escape Flaws in Chrome 149
June 30, 2026
119 Edge Extensions Hidden Stego Malware Reaches 2.6 Million Installs
June 30, 2026
U.S. State Department Offers $10 Million Reward for Russian Hacker Groups Targeting Encrypted Messaging Apps
June 30, 2026

Related Stories

CSBadmin

Miasma Worm Exploits Node GYP Build File to Inject Malicious Code in npm Packages

CSBadmin

Lazarus Group Targets macOS Users With ‘Mach-O Man’ Malware Kit Aimed at Crypto and Fintech

CSBadmin

Self-Replicating Miasma Worm Breaches Dozens of Microsoft GitHub Repositories

CSBadmin

Generative AI Tools Fuel GREYVIBE Cyberattacks Targeting Ukraine

csb-sized
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Cybersecurity Beat. All rights reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?