← Back to Feed
EvilTokens: A phishing attack that doesn’t steal your password
June 15, 2026 · WeLiveSecurity · Severity: LOW
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
Key Takeaways
- ESET detailed EvilTokens, a phishing kit that subverts Microsoft's legitimate authentication flow to break into accounts.
- The EvilTokens approach works without stealing passwords or creating fake login pages, subverting Microsoft's legitimate authentication flow instead.
- Users should enable phishing-resistant MFA, since token-theft phishing techniques like EvilTokens bypass traditional password protections.