Cybersecurity researchers have disclosed a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies, which is used as a proxy to redirect Microsoft 365…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
EvilTokens is an attack group conducting ghost phishing campaigns targeting US and European businesses. They use Microsoft Device Code Phishing and AES-GCM…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
Flare is a cybersecurity company that provides threat intelligence and digital risk monitoring. Flare security researcher Assaf Morag commented on EvilTokens, noting…