EvilTokens: Big Cybercrime’s AI Platform Built to Bypass Your MFA

EvilTokens: Big Cybercrime’s AI Platform Built to Bypass Your MFA

Source: YouTube · Huntress · published May 6, 2026 · 53:57

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: The video details a massive, 16-day phishing campaign targeting 344 organizations via a "Device Code" attack vector, highlighting how adversaries rapidly exploit new authentication methods 0:15.

Key Takeaways:
• Initial alerts appeared as individual, low-level events, but analysts recognized the threat when the same cloud IP targeted 50 organizations in one week 0:11.
• The campaign utilized "Device Code Phishing," a technique where victims are tricked into authorizing a device to access their account without entering a password 0:18.
• The operation was driven by "Evil Tokens," a phishing-as-a-service platform that allows attackers to easily deploy and manage these campaigns 0:41.
• Adversaries are adopting AI and new technologies early to find exploits before defenses can adapt, moving aggressively to capitalize on innovations 0:32.
• The scale of the incident involved hundreds of incident reports across 344 organizations, demonstrating the widespread impact of such infrastructure 0:27.

Closing Statement: This case study underscores the critical need for monitoring anomalous authentication patterns and understanding emerging phishing techniques like Device Code phishing to prevent large-scale breaches.

Sources:

  • 0:15 Discussion on identifying the phishing campaign through repeated IP hits across multiple organizations.
  • 0:18 Explanation of the "Device Code" phishing technique used in the attacks.
  • 0:27 Overview of the campaign's scale, affecting 344 organizations within 16 days.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

These were individual alerts, the kind that don't immediately set off alarm bells. >> Usually what we see these fishing campaigns is it'll be one or two days of activity and that the tradecraftraft changes or the infrastructure changes. >> But if you see the same cloud IP hit 50 organizations within the same week, suddenly you know that it's not just this weird blip >> all from the railway organization, all with the same attributes of device code fishing. By this time, our analysts has started pulling on the thread, and we're staring at what would become hundreds of incident reports across 344 organizations, all within 16 days. >> Adversaries adopted AI early, moving quickly and aggressively, knowing that for every innovation, there's an exploit. >> Evil Tokens is a fishing as a service pl…