By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Cybersecurity Beat
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
Reading: New PhishingKit Exploits Browser Side Decryption to Hide Microsoft 365 Account Takeover
  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
Cybersecurity BeatCybersecurity Beat
Font ResizerAa
Search
  • News & Alerts
  • Articles
  • Spotlight
  • Features
  • Resources
Follow US
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

New PhishingKit Exploits Browser Side Decryption to Hide Microsoft 365 Account Takeover

The EvilTokens phishing kit encrypts its landing page content with AES GCM to bypass static URL analysis, exploiting Microsoft's device code login process for account takeover.

CSBadmin
Last updated: July 3, 2026 10:38 pm
CSBadmin
2 Min Read
Share
SHARE

How the Attack Works

A sophisticated phishing kit known as EvilTokens is targeting organizations across the United States and Europe, using a technique that hides its malicious activity from traditional security tools. The attack exploits Microsoft’s legitimate device code authentication flow, tricking victims into granting access to their own Microsoft 365 accounts without the attackers ever capturing passwords directly.

Contents
How the Attack WorksImpact and Scope

The kit’s effectiveness stems from its use of encrypted landing page HTML. The page content is encrypted using AES GCM and only becomes readable within the victim’s browser after decryption occurs. This means static URL analysis and network level detection tools often miss the actual phishing content, recording only an encrypted response while never revealing what the victim sees on screen.

Impact and Scope

Security researchers have identified EvilTokens activity concentrated primarily across the United States and Europe, targeting sectors including managed security services, technology, manufacturing, education, banking, and consulting. The kit focuses on environments where a single compromised Microsoft 365 account provides access to sensitive data, internal communications, and linked business services.

The encrypted approach creates significant challenges for security operations teams. When analysts cannot observe what a suspicious page does after execution in the browser, the consequences include longer exposure to potential account compromise, delayed containment decisions, increased alert volumes for senior staff, higher investigation costs, and incomplete evidence for blocking related infrastructure. Security teams need browser level analysis capabilities to detect the decrypted phishing content and confirm threats rapidly.

Source: Cyber Security News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account TakeoverEvilTokens
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Water Utilities Targeted Through Weak PLC Security and Exposed Controls
Next Article Conditional Access Bypass Exploits Microsoft Entra Nested App Flow

Trending

AmnesiaStealer trades keychain dumps for live macOS browser hijacks
August 14, 2026
Free 15.5 GB dump puts 7.3 million Chess.com accounts at risk
August 14, 2026
Probes hit GeoServer SQLi zero-day within hours of disclosure
August 14, 2026
Akira’s Safe Mode play blinds EDR but crashes its own encryptor
August 14, 2026
Session swap bug in Adobe Commerce draws attacks right after patch
August 14, 2026

Related Stories

CSBadmin

Generative AI Tools Fuel GREYVIBE Cyberattacks Targeting Ukraine

CSBadmin

Abbott discloses cyberattack on its cancer diagnostics business

CSBadmin

Zimbra Classic Web Client Vulnerability Allows Code Execution via Malicious Emails

CSBadmin

Supply Chain Attack Targets Checkmarx Users Through Malicious Docker Images and Extensions

csb-sized
  • About CSB
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Cybersecurity Beat. All rights reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?