<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows.]]></title><description><![CDATA[<p><a href="https://infosec.exchange/tags/TDR" rel="tag">#<span>TDR</span></a> analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called <a href="https://infosec.exchange/tags/EvilTokens" rel="tag">#<span>EvilTokens</span></a>, which offers device code phishing pages and AI-augmented features to automate and scale <a href="https://infosec.exchange/tags/BEC" rel="tag">#<span>BEC</span></a> workflows. <br /><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2b07.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--arrow_down" style="height:23px;width:auto;vertical-align:middle" title="⬇" alt="⬇" />️ <br /><a href="https://buff.ly/RvF5Kux" rel="nofollow noopener"><span>https://</span><span>buff.ly/RvF5Kux</span><span></span></a></p>]]></description><link>https://board.circlewithadot.net/topic/50e2466c-66cb-496f-b9db-2785860ff5f1/tdr-analysts-uncovered-an-emerging-phishing-as-a-service-phaas-platform-called-eviltokens-which-offers-device-code-phishing-pages-and-ai-augmented-features-to-automate-and-scale-bec-workflows.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 04:04:04 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/50e2466c-66cb-496f-b9db-2785860ff5f1.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 30 Mar 2026 15:56:26 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to #TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. on Mon, 30 Mar 2026 15:56:27 GMT]]></title><description><![CDATA[<p>Our report offers a technical analysis of the EvilTokens kit, its delivery campaigns, and the adversary's infrastructure.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/sekoia_io/statuses/116318941154191279</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/sekoia_io/statuses/116318941154191279</guid><dc:creator><![CDATA[sekoia_io@infosec.exchange]]></dc:creator><pubDate>Mon, 30 Mar 2026 15:56:27 GMT</pubDate></item><item><title><![CDATA[Reply to #TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. on Mon, 30 Mar 2026 15:56:26 GMT]]></title><description><![CDATA[<p>Active since late February 2026 and rapidly adopted by cybercriminals, TDR analysts believe EvilTokens will become a serious competitor in the phishing and BEC landscape.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/sekoia_io/statuses/116318941127946746</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/sekoia_io/statuses/116318941127946746</guid><dc:creator><![CDATA[sekoia_io@infosec.exchange]]></dc:creator><pubDate>Mon, 30 Mar 2026 15:56:26 GMT</pubDate></item><item><title><![CDATA[Reply to #TDR analysts uncovered an emerging Phishing-as-a-Service (#PhaaS) platform called #EvilTokens, which offers device code phishing pages and AI-augmented features to automate and scale #BEC workflows. on Mon, 30 Mar 2026 15:56:26 GMT]]></title><description><![CDATA[<p>EvilTokens device code phishing pages allows attackers to capture Microsoft refresh and access token, weaponise them, harvest victims' mailbox, and automatically craft BEC emails using AI.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/sekoia_io/statuses/116318941106977843</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/sekoia_io/statuses/116318941106977843</guid><dc:creator><![CDATA[sekoia_io@infosec.exchange]]></dc:creator><pubDate>Mon, 30 Mar 2026 15:56:26 GMT</pubDate></item></channel></rss>