← Back to Feed

EvilTokens: A phishing attack that doesn’t steal your password

June 15, 2026 · WeLiveSecurity · Severity: LOW

A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages

Key Takeaways

  • ESET detailed EvilTokens, a phishing kit that subverts Microsoft's legitimate authentication flow to break into accounts.
  • The EvilTokens approach works without stealing passwords or creating fake login pages, subverting Microsoft's legitimate authentication flow instead.
  • Users should enable phishing-resistant MFA, since token-theft phishing techniques like EvilTokens bypass traditional password protections.
☕ Buy a Coffee