By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: New PhishingKit Exploits Browser Side Decryption to Hide Microsoft 365 Account Takeover
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

New PhishingKit Exploits Browser Side Decryption to Hide Microsoft 365 Account Takeover

The EvilTokens phishing kit encrypts its landing page content with AES GCM to bypass static URL analysis, exploiting Microsoft's device code login process for account takeover.

CSBadmin
Last updated: July 3, 2026 10:38 pm
CSBadmin
2 Min Read
Share
SHARE

How the Attack Works

A sophisticated phishing kit known as EvilTokens is targeting organizations across the United States and Europe, using a technique that hides its malicious activity from traditional security tools. The attack exploits Microsoft’s legitimate device code authentication flow, tricking victims into granting access to their own Microsoft 365 accounts without the attackers ever capturing passwords directly.

Contents
How the Attack WorksImpact and Scope

The kit’s effectiveness stems from its use of encrypted landing page HTML. The page content is encrypted using AES GCM and only becomes readable within the victim’s browser after decryption occurs. This means static URL analysis and network level detection tools often miss the actual phishing content, recording only an encrypted response while never revealing what the victim sees on screen.

Impact and Scope

Security researchers have identified EvilTokens activity concentrated primarily across the United States and Europe, targeting sectors including managed security services, technology, manufacturing, education, banking, and consulting. The kit focuses on environments where a single compromised Microsoft 365 account provides access to sensitive data, internal communications, and linked business services.

The encrypted approach creates significant challenges for security operations teams. When analysts cannot observe what a suspicious page does after execution in the browser, the consequences include longer exposure to potential account compromise, delayed containment decisions, increased alert volumes for senior staff, higher investigation costs, and incomplete evidence for blocking related infrastructure. Security teams need browser level analysis capabilities to detect the decrypted phishing content and confirm threats rapidly.

Source: Cyber Security News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverEvilTokens
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Water Utilities Targeted Through Weak PLC Security and Exposed Controls
Next Article Conditional Access Bypass Exploits Microsoft Entra Nested App Flow

Trending

A 2005 forum dump shows how little ransomware culture has changed
A 2005 forum dump shows how little ransomware culture has changed
September 29, 2026
Making an AI sound drunk makes it spill secrets and break rules
Making an AI sound drunk makes it spill secrets and break rules
September 29, 2026
US phone forensics vendor accused of hiding its Russian owners
US phone forensics vendor accused of hiding its Russian owners
September 29, 2026
One ransomware crew pivots between four brands with the same playbook
One ransomware crew pivots between four brands with the same playbook
September 29, 2026
A hidden field in DC health reports exposed 400,000 Medicaid files
A hidden field in DC health reports exposed 400,000 Medicaid files
September 29, 2026

Related Stories

CSBadmin

cPanel parking flaw lets tenants plant files as root user

OpenAI agents flooded RubyGems with thousands of fake packages
CSBadmin

OpenAI agents flooded RubyGems with thousands of fake packages

CSBadmin

Single Character Error in Linux Kernel Opens Door to Full System Takeover

CSBadmin

JavaScript IPC Library Node ipc Used in Fresh Supply Chain Attack

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.