[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAn8MSMpasRgT0whVNumFvw7YLHEjd38-7MtcpMiTWFQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"c8843437-a53d-4eef-9136-387e32877e27","ai-driven-phishing-platform-bypasses-mfa-via-oauth-device-code-abuse","bdf556e4-9242-4aae-9fb3-a9b73daab0b2","AI-Driven Phishing Platform Bypasses MFA via OAuth Device Code Abuse","EvilTokens represents a new class of phishing-as-a-service that exploits legitimate OAuth device code flows to steal session tokens, effectively rendering traditional MFA protections useless without requiring credential theft. By abusing trusted cloud infrastructure (Railway, BL Networks), attackers blend malicious traffic with legitimate services, making detection extremely difficult for standard email and network filters. The 1,380% surge in attacks highlights how AI-generated personalized lures dramatically lower the skill barrier for cybercriminals while increasing victim success rates. Organizations that rely solely on MFA as a security boundary are now dangerously exposed, as token-based session hijacking sidesteps authentication entirely. This campaign underscores that MFA is a necessary but insufficient control when OAuth consent and device code flows are left unrestricted.","**Immediate actions:**\n- Disable or restrict the OAuth device code flow in Azure AD \u002F Entra ID Conditional Access policies for all non-essential use cases.\n- Enable Conditional Access policies that block token issuance from unknown or untrusted devices and locations.\n- Audit all existing OAuth application consents in Microsoft 365 and revoke permissions granted to unrecognized third-party apps.\n\n**Detection measures:**\n- Deploy anomalous OAuth token sign-in alerts in Microsoft Sentinel or your SIEM to flag device code flow authentications from unusual IPs or geographies.\n- Monitor for sign-ins originating from Railway, BL Networks, or other unexpected cloud hosting providers as potential indicators of compromise.\n- Implement User and Entity Behavior Analytics (UEBA) to detect abnormal post-authentication activity patterns indicative of session token replay.\n\n**Long-term improvements:**\n- Transition to phishing-resistant MFA methods (FIDO2\u002Fpasskeys) that are cryptographically bound to the origin and cannot be replayed via token theft.\n- Conduct regular security awareness training specifically covering OAuth consent phishing and device code flow attack scenarios.\n- Establish a formal OAuth application governance program that enforces allowlisting and periodic re-certification of approved integrations.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"NIST SP 800-63B (Authentication Assurance Levels)","NIST AC-17 (Remote Access)","NIST AC-20 (Use of External Information Systems)","NIST SI-3 (Malicious Code Protection)","CIS Control 4 (Secure Configuration of Enterprise Assets)","CIS Control 6 (Access Control Management)","CIS Control 9 (Email and Web Browser Protections)","CIS Control 13 (Network Monitoring and Defense)","MITRE ATT&CK T1528 (Steal Application Access Token)","MITRE ATT&CK T1566 (Phishing)","GDPR Article 32 (Security of Processing)","Microsoft Secure Score – Identity Secure Score recommendations","ITIL Service Security Management – Threat & Vulnerability Management","published","2026-06-24T16:22:32.269012+00:00","2026-06-24T16:22:32.143+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F06\u002F24\u002Fai-powered-phishing-attacks-surge-1380-as-criminal-platforms-render-mfa-obsolete\u002F?utm_source=rss&utm_medium=rss&utm_campaign=ai-powered-phishing-attacks-surge-1380-as-criminal-platforms-render-mfa-obsolete","ai-powered-phishing-attacks-surge-1-380-as-criminal-platforms-render-mfa-obsolet-2ee76d","AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]