Hackers Use AI-Generated Code to Build EvilTokens Infrastructure, Accelerating Device-Code Phishing
Device-code authentication was designed to let users authorize keyboardless devices for Microsoft 365 simply by entering a code. Hackers can exploit the mechanism by tricking victims into granting authorization, bypassing multifactor authentication and obtaining access tokens. Once stolen, the tokens can expose corporate email, files and sensitive data.
In July 2026, cybersecurity company Proofpoint disclosed a new phishing infrastructure called EvilTokens. Using AI-generated programs in a “vibe coding” approach, attackers dynamically create and modify code specifically to scale device-code phishing attacks, steal Microsoft 365 tokens, and automate account takeovers and information theft.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.