ET PHISHING EvilTokens Poll for user_code Authentication Status
Sourceet/open
CreatedApril 7, 2026
UpdatedApril 8, 2026
Classificationcredential-theft
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET PHISHING EvilTokens Poll for user_code Authentication Status"; flow:established,to_server; flowbits:isset,ET.EvilTokens; http.method; content:"GET"; http.uri; content:"/api/device/status/"; fast_pattern; startswith; reference:url,blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/; classtype:credential-theft; sid:2068630; rev:1; metadata:affected_product MS_Outlook, affected_product Microsoft_OneDrive, affected_product Microsoft_Sharepoint, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2026_04_07, deployment Perimeter, confidence High, signature_severity Critical, tag EvilTokens, updated_at 2026_04_08;)
Metadata
affected productMicrosoft_Sharepoint
attack targetClient_Endpoint
tls stateTLSDecrypt
created at2026_04_07
deploymentPerimeter
confidenceHigh
signature severityCritical
tagEvilTokens
updated at2026_04_08
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!