Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Cybercriminals

The “EvilTokens” Surge: Why Device Code Phishing Exploded 37-Fold in 2026

by Nam Phong · April 7, 2026

The architecture of account exploitation is undergoing a profound metamorphosis, as adversaries increasingly eschew traditional subversion in favor of co-opting legitimate authorization frameworks. At a cursory glance, the procedure appears innocuous; however, therein lies the quintessence of the peril: the victim unwittingly unlatches the gates to their own sanctuary, oblivious to the underlying artifice.

Specialists have chronicled a precipitous surge in offensives leveraging “Device Codes”—an escalation exceeding 37-fold within a singular calendar year. This phenomenon involves the systemic abuse of the OAuth 2.0 Device Authorization Grant, a protocol originally conceived to facilitate seamless authentication for apparatuses lacking keyboards or possessing constrained input capabilities, such as smart televisions, printers, or IoT peripherals.

The offensive trajectory is strikingly uncomplicated. An assailant initiates an authorization request to secure a bespoke code, which is then surreptitiously conveyed to the victim under various pretenses—frequently via electronic missives or instant messaging conduits. Once the user enters this code upon an authentic login portal, they effectively validate access to their account, granting the adversary valid tokens and absolute dominion over the session.

While this technique has been recognized since 2020, its ubiquitous application has only recently matured. It is no longer a localized anomaly; the method is now wielded en masse by both fiscally motivated syndicates and highly orchestrated state actors.

The Push Security vanguard observes that the proliferation of this threat has been catalyzed by sophisticated toolkits marketed under the “Phishing-as-a-Service” model. Most prominent is the EvilTokens suite, which has significantly lowered the barrier to entry, rendering such incursions accessible even to neophyte actors. Concurrently, a burgeoning ecosystem of rival platforms is emerging to contest this niche.

Notable among these are VENOM, SHAREFILE, CLURE, LINKID, AUTHOV, and DOCUPOLL. The majority of these frameworks masquerade as ubiquitous SaaS environments, including Microsoft 365, DocuSign, Adobe, and corporate collaboration tools like Teams. To augment their efficacy, these platforms employ anti-bot filtrations, fraudulent landing pages, and cloud-based infrastructures.

Certain kits meticulously simulate legitimate professional workflows, such as the dispatch of documents for signature or notifications from human resources. This tactical refinement mitigates suspicion, increasing the likelihood that a user will input the code without hesitation.

Experts counsel the restriction of Device Code authorization in environments where its utility is non-essential. Furthermore, the rigorous interrogation of authentication logs—monitoring for unsolicited authorization attempts, anomalous IP addresses, and irregular session behaviors—remains a vital defensive measure. The ascendancy of such offensives illustrates that marauders are increasingly predicated not upon technical vulnerabilities, but upon the weaponization of user trust and the legitimate mechanisms of modern services.

Related coverage

  • OVERCAST PANDA Conducts Physical Attacks on Laptops
  • AI Cyber Threat Trends Surge in 2025
  • Student Hacks IIT Websites After Cyber Security Rejection
  • SilverFox ValleyRAT Attack Targets Japanese Industry via Phishing
  • TA488 OWAReaper Outlook Exploit Bypasses Passwords

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Account TakeoverCybersecurity 2026Device Code PhishingEvilTokensInfosecMicrosoft 365OAuth 2.0Phishing-as-a-ServicePush SecurityToken Theft

Follow:

  • Next story The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
  • Previous story Cultural Crisis: How the Vivaticket Ransomware Attack Paralyzed the Louvre and 3,500 European Landmarks

  • Recent Posts
  • Popular Posts
  • Tags
  • ENDLESSDOORS hidden backdoor in Zbtlink router firmware discovered by VulnCheck using rctl remote control Linux component masquerading as kernel threads with root access

    Vulnerability

    ENDLESSDOORS: Hidden Remote Control Found in Zbtlink Router Firmware

    August 7, 2026

  • iCloud Private Relay IP leak via three WebKit vulnerabilities DNS prefetch WebAuthn WebTransport bypassing proxy on iOS iPadOS macOS Safari and third-party browsers

    Vulnerability

    iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses

    August 7, 2026

  • Malware bypassing DNS security by connecting directly to C2 IP addresses Phorpiex SectopRAT Mozi botnet ZT-IP firewall detection Unit 42

    Malware

    45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses

    August 7, 2026

  • Tactical police unit responding to coordinated swatting attacks with emergency vehicles

    Cyber Security

    FBI Warns of Coordinated Swatting Attacks Nationwide

    August 7, 2026

  • Tails 7.10.1 emergency patch for CVE-2026-64560 Linux kernel POSIX CPU timer race condition allowing Tor Browser privilege escalation and user deanonymization

    Linux

    Tails 7.10.1: Emergency Patch for CVE-2026-64560 That Could Deanonymize Users

    August 7, 2026

  • VMware vCenter vulnerability CVE-2026-59309 and CVE-2026-59310 rated CVSS 9.8 authentication bypass

    Vulnerability Report

    VMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8

    July 29, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source Penetration Testing phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro