Mark RadarMARK RADAR
EN
Event File AI Cyberattacks

Hackers Use AI-Generated Code to Build EvilTokens Infrastructure, Accelerating Device-Code Phishing

1 reports · First detected 2026-05-18 · Last active 2026-05-18

Device-code authentication was designed to let users authorize keyboardless devices for Microsoft 365 simply by entering a code. Hackers can exploit the mechanism by tricking victims into granting authorization, bypassing multifactor authentication and obtaining access tokens. Once stolen, the tokens can expose corporate email, files and sensitive data.

In July 2026, cybersecurity company Proofpoint disclosed a new phishing infrastructure called EvilTokens. Using AI-generated programs in a “vibe coding” approach, attackers dynamically create and modify code specifically to scale device-code phishing attacks, steal Microsoft 365 tokens, and automate account takeovers and information theft.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)