0x742 - Teknik - EvilTokens

0x742 - Teknik - EvilTokens

🎙 PolySécure Podcast 👥 540 📅 April 10, 2026 ⏱ 30 min 👁 60 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

phishingdevice codeAIBECcybersecurity

Summary

In this technical episode, the host interviews Quentin Bourgue, a cybersecurity researcher, about a new phishing-as-a-service (PhaaS) platform called EvilTokens. Discovered in early March 2026 via Telegram, EvilTokens offers a subscription-based phishing kit that uses device code phishing instead of the more common adversary-in-the-middle (AiTM) technique. This method leverages legitimate Microsoft domains, making detection harder. The attacker obtains an access token and a primary refresh token, granting persistent access for up to 90 days. The platform is notable for its AI-powered post-compromise automation: it uses Microsoft Graph API to collect victim data and two Groq LLM models to analyze emails, generate fraud scores, and draft three BEC emails ready to send. The service costs $1,500 upfront plus $500 monthly, higher than competitors, justified by advanced features. The code appears to be AI-generated (vibe-coded). The podcast discusses the implications for organizations, recommending blocking or restricting device code authorization and training employees. The researcher predicts that competitors like Kratos and Tycoon will quickly adopt similar techniques, making AI-enhanced phishing more widespread.

169 words

Critical Evaluation

Value of the Information & Strength of the Argument

The podcast provides valuable insights into an emerging cyber threat, detailing the technical aspects of EvilTokens and its AI-driven capabilities. The argumentation is solid, based on the researcher’s direct investigation and analysis. The discussion highlights the evolution of phishing attacks and the increasing accessibility of sophisticated techniques to less skilled attackers. The value lies in raising awareness and providing actionable recommendations for defense.

Scientific Rigor, Source Quality, Title Accuracy

The podcast demonstrates scientific rigor by referencing specific technical details, such as the use of Groq LLM models and Microsoft Graph API. The researcher mentions that the analysis is based on their own investigation, but no external sources are cited. The title accurately reflects the content. The discussion is well-structured and technically accurate, though it relies on the researcher’s expertise rather than peer-reviewed sources.

142 words

Title / Content Match

The title accurately reflects the content, focusing on the technical analysis of the EvilTokens phishing kit.

Quality & Reliability

8/10

The podcast features a cybersecurity researcher discussing a detailed analysis of a new phishing-as-a-service kit. The information is technical and specific, based on the researcher's investigation. However, it is presented as an expert opinion without formal peer review or external verification.

Key Moments

Cited Sources

  • EvilTokens: A New Phishing-as-a-Service with AI-Powered Post-Compromise — The researcher mentions publishing a two-part report on EvilTokens, which is the basis for this podcast.

Concurring Sources

Contribution & Novelties

This podcast provides an in-depth analysis of a novel phishing-as-a-service platform that combines device code phishing with AI-driven post-compromise automation. It highlights the convergence of advanced phishing techniques and AI, making sophisticated attacks accessible to less skilled cybercriminals. The discussion offers valuable insights for cybersecurity professionals and emphasizes the need for adaptive defense strategies.

Pour aller plus loin :

  • Device Code Authentication — Explains the OAuth 2.0 device authorization grant used in the attack.
  • Business Email Compromise — FBI overview of BEC scams.
  • Microsoft Graph API — Official documentation on the API used for data exfiltration.

96 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and technical level, with slightly lower reliability due to the reliance on expert opinion. This indicates a technically rich and informative discussion, but one that would benefit from external verification.

Reliability 7/10