f6b14be2-e71f-4843-9982-65f316e75ca3

Inside EvilTokens: The PhaaS Platform Stealing Tokens, Not Passwords

EvilTokens is a phishing-as-a-service platform that sidesteps traditional defenses by hijacking account access through a legitimate Microsoft login flow—then deploys AI to automate business email compromise at scale. 

Unlike credential-harvesting attacks, EvilTokens never asks victims to enter a password on a fake page. Instead, targets authenticate directly on Microsoft infrastructure while the platform silently captures OAuth tokens and converts them into a persistent, fully-operational BEC toolkit. Join Abnormal Intelligence as they break down how EvilTokens works, why it bypasses conventional controls, and what security teams can do to reduce exposure.

I OAuth Token Theft · Microsoft Login Hijack · AI-Driven BEC


I would like to receive email updates about thought leadership and industry news from Abnormal. By submitting this form, you agree to the terms in our privacy policy.