Real MFA. Account stolen.
EvilTokens Taken Down — But Device Code Phishing Is Not Going Away
Microsoft and partners disrupted EvilTokens, a phishing service linked to more than 12,000 compromised inboxes. Victims typed a code into a genuine Microsoft page, passed MFA — and unknowingly approved the attacker's session. A new kit, GhostCode, is already using the same trick against sales teams via website contact forms.