AI-Powered Device Code Phishing Platform Compromises 12,000+ Inboxes
EvilTokens exploited the OAuth device code authentication flow — a legitimate mechanism designed for input-constrained devices — to trick users into granting persistent access tokens to attackers, bypassing traditional credential-based defenses like MFA. Because device code authentication tokens remain valid even after password resets, attackers achieved long-term persistence inside victim environments without needing ongoing user interaction. The use of AI to craft highly personalized phishing lures dramatically lowered the skill barrier for launching convincing Business Email Compromise campaigns at scale. This attack chain highlights how legitimate platform features can be weaponized when organizations lack controls restricting which authentication flows are permitted. The consequences extend beyond individual inboxes, as compromised accounts are frequently leveraged for lateral movement, financial fraud, and further phishing campaigns targeting trusted contacts.
Tactical Insight
Immediate actions
- Restrict or disable the OAuth device code authentication flow for users who do not require it via Conditional Access policies in your identity provider.
- Audit all existing OAuth application consents and revoke any tokens associated with unrecognized or suspicious applications.
- Force token revocation and re-authentication for all accounts suspected of compromise, as password resets alone do not invalidate stolen tokens.
Long-term improvements
- Implement phishing-resistant MFA (e.g., FIDO2/passkeys) organization-wide to reduce reliance on token-based authentication flows that can be abused.
- Establish an allowlist of approved OAuth applications and enforce policies that block user consent to unvetted third-party apps.
- Conduct regular security awareness training specifically covering device code phishing, QR code lures, and consent phishing techniques.
Detection measures
- Enable and monitor sign-in logs and OAuth consent grants for anomalous device code authentication requests originating from unexpected locations or devices.
- Configure alerts for high-volume email access, inbox rule creation, or forwarding rules that may indicate a compromised mailbox being exploited for BEC.
- Integrate threat intelligence feeds to identify known PhaaS infrastructure (e.g., EvilTokens C2 domains) and block them at the network perimeter.