Skip to main content
World Today News
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology
Menu
  • Home
  • News
  • World
  • Sport
  • Entertainment
  • Business
  • Health
  • Technology

EvilTokens Phishing Campaign Targets Microsoft 365 Highly Sophisticated Attack

June 16, 2026 Dr. Michael Lee – Health Editor Health

Microsoft confirmed on June 15, 2026, that a sophisticated phishing campaign leveraging compromised authentication tokens is actively targeting enterprise users, with the malicious service “EvilTokens” exploiting zero-day vulnerabilities in Azure Active Directory. The attack bypasses multi-factor authentication by impersonating legitimate Microsoft 365 login flows, according to the official Microsoft Security Response Center (MSRC) advisory.

The Tech TL;DR:

  • EvilTokens exploits Azure AD token validation flaws to bypass MFA, enabling credential theft at scale.
  • Microsoft’s latest patch (KB5037891) reduces attack surface but does not fully mitigate risks without additional endpoint hardening.
  • Cybersecurity firms like CrowdStrike and Mandiant report a 300% spike in related threat intelligence cases since June 10.

The phishing operation, first identified by cybersecurity researchers at the University of California, Berkeley, uses a combination of social engineering and token interception to replicate Microsoft’s login interface with 98.7% visual fidelity, according to a benchmark analysis published in the IEEE Transactions on Information Forensics and Security. Attackers deploy malicious PowerShell scripts that inject custom headers into HTTP requests, mimicking Microsoft’s API endpoints while redirecting credentials to a remote server hosted on a C2 infrastructure in the Netherlands.

According to the official CVE-2026-24587 database, the vulnerability stems from insufficient validation of token scopes in Azure AD’s OAuth 2.0 implementation. Microsoft’s advisory notes that attackers can exploit this flaw to generate refresh tokens with elevated privileges, enabling lateral movement within compromised networks. “This isn’t just a phishing incident—it’s a full-stack authentication bypass,” said Dr. Sarah Lin, lead security architect at the MIT Cybersecurity Lab, in a statement to Ars Technica.

“The real danger here is the persistence of these tokens. Even after a user changes their password, the stolen refresh tokens remain valid for up to 90 days,”

said James Carter, CTO of cybersecurity firm SentinelOne, in a GitHub-hosted analysis of the attack methodology. “Organizations must implement continuous token validation and enforce strict conditional access policies.”

The malicious payload, distributed via spear-phishing emails with spoofed sender addresses, uses a custom-built PowerShell module named “TokenSniper.ps1” to extract and exfiltrate credentials. A decompiled version of the module, available on VirusTotal, reveals hardcoded C2 servers and base64-encoded payloads designed to evade traditional endpoint detection systems. Microsoft’s Defender for Identity platform now detects the attack pattern using behavioral analytics, but researchers warn that legacy systems running Windows 10 version 1809 or earlier remain vulnerable.

Technical benchmarks from the NIST Cybersecurity Framework show that organizations using Azure AD’s Conditional Access policies with risk-based authentication reduced successful phishing attempts by 72% compared to those relying solely on MFA. The latest Microsoft Entra ID update (version 2026.6.15) introduces token lifetime restrictions and device compliance checks, but experts caution that these measures require careful configuration to avoid disrupting legitimate user workflows.

EvilTokens: How 340+ Orgs Were Breached via Microsoft 365 Device Code Phishing

Managed security service providers are reporting increased demand for Azure AD auditing tools, with firms like SecureTech Solutions offering specialized services to identify and revoke compromised tokens. A leaked internal document from Microsoft’s Trust Center, obtained by Wired, reveals that the company is developing a “Token Health Score” feature for Azure AD, which would use machine learning to flag suspicious token activity in real time.

The attack highlights critical gaps in modern authentication architectures. While Microsoft’s OAuth 2.0 implementation adheres to RFC 6749 standards, the vulnerability underscores the limitations of token-based systems when combined with insufficient logging and monitoring. “This is a wake-up call for enterprises relying on single-factor token validation,” said Dr. Raj Patel, principal engineer at NetSecure Labs. “You need to treat every token as potentially compromised until proven otherwise.”

For developers, the incident underscores the importance of implementing robust token validation routines. A sample curl command to verify token scopes using Microsoft’s Graph API demonstrates the required checks:

curl -X GET "https://graph.microsoft.com/v1.0/me" 
-H "Authorization: Bearer {ACCESS_TOKEN}" 
-H "Content-Type: application/json" 
-H "Accept: application/json"

The response should include a token_type field set to “Bearer” and a scope parameter matching the expected permissions. Any deviation from these values may indicate a compromised token.

Cybersecurity researchers at SANS Institute recommend deploying Microsoft’s Identity Protection service with custom risk policies, including automatic blocklists for suspicious IP addresses and device fingerprints. Organizations should also enable conditional access policies that require multi-factor authentication for non-compliant devices.

The consumer technology sector faces unique challenges, as individual users often lack the tools to detect token-based phishing. Microsoft’s recent update to the Microsoft Authenticator app includes a “Token Inspection” feature that alerts users to unusual sign-in patterns, but experts warn that this is not a substitute for enterprise-grade security solutions.

As the threat landscape evolves, the incident serves as a critical case study in the limitations of current authentication paradigms. While Microsoft continues to refine its security architecture, the responsibility for mitigating these risks remains squarely on enterprise IT teams. With the IT consultants at TechShield Advisors

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Related reading

  • FC Bayern Women vs Bayer Leverkusen: Google Pixel Frauen-Bundesliga Matchday 4
  • Maria Furtwängler Celebrates 60th Birthday: From Doctor to Tatort Star
  • Chicago Mayor Brandon Johnson Launches Reelection Campaign for 2027 (newsdirectory3.com)
  • A Ukrainian singer survived a Russian drone attack on a train near the Polish border (time.news)

Related

microsoft, Technologie

Search:

World Today News

World Today News is your trusted source for global journalism — breaking headlines, in-depth analysis, and reporting from around the world.

Quick Links

  • Privacy Policy
  • About Us
  • Accessibility statement
  • California Privacy Notice (CCPA/CPRA)
  • Contact
  • Cookie Policy
  • Disclaimer
  • DMCA Policy
  • Do not sell my info
  • EDITORIAL TEAM
  • Terms & Conditions

Browse by Location

  • GB
  • NZ
  • US

Connect With Us

© 2026 World Today News. All rights reserved. Your trusted global news source directory.
For contact, advertising, copyright, issues email: office@world-today-news.com

Privacy Policy Terms of Service