Microsoft Threat Intelligence Podcast

Eviltokens: A Conversation with Huntress on an AI‑Enabled Device Code Phishing Campaign


Listen Later

In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠Sherrod DeGrippo joins researchers from Huntress to break down the rise of EvilTokens, an AI-powered phishing-as-a-service platform designed to bypass MFA and automate credential theft at scale. Together, they explore how attackers are leveraging legitimate authentication flows, trusted infrastructure, and AI-generated phishing lures to blend malicious activity into normal enterprise traffic. The conversation also examines how modern phishing operations have evolved into highly professionalized cybercrime ecosystems and what defenders must do to adapt their identity security strategies.  


In this episode you’ll learn:      

  • How EvilTokens bypasses MFA using device code phishing 

    • Why AI-powered phishing campaigns are harder to detect 

      • What makes modern phishing kits highly scalable and automated 

        Some questions we ask:     

        • What role does trusted infrastructure play in these attacks? 

          • Why are traditional phishing defenses struggling against these tactics? 

            • How are modern phishing kits becoming more professionalized? 

              Resources:  

              • Watch the LinkedIn live recording 

                • Read Huntress’ related research 

                  • View Lindsay O’Donnell-Welch on LinkedIn 

                    • View Jamie Levy on LinkedIn 

                      • View Sherrod DeGrippo on LinkedIn  

                        Related Microsoft Podcasts:                   

                        • Security Insider Conversations 

                          • The BlueHat Podcast 

                            • Uncovering Hidden Risks     


                              Discover and follow other Microsoft podcasts at microsoft.com/podcasts  

                               

                              Get the latest threat intelligence insights and guidance at Microsoft Security Insider 

                               

                              The Microsoft Threat Intelligence Podcast is produced by Microsoft, Hangar Studios and distributed as part of N2K media network. 

                              ...more
                              View all episodesView all episodes
                              Download on the App Store

                              Microsoft Threat Intelligence PodcastBy Microsoft

                              • 5
                              • 5
                              • 5
                              • 5
                              • 5

                              5

                              22 ratings


                              More shows like Microsoft Threat Intelligence Podcast

                              View all
                              Hacked by Hacked

                              Hacked

                              190 Listeners

                              Security Now (Audio) by TWiT

                              Security Now (Audio)

                              2,007 Listeners

                              The Talk Show With John Gruber by Daring Fireball / John Gruber

                              The Talk Show With John Gruber

                              3,144 Listeners

                              Risky Business by Risky Business Media

                              Risky Business

                              376 Listeners

                              SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

                              SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

                              649 Listeners

                              CyberWire Daily by N2K Networks

                              CyberWire Daily

                              1,027 Listeners

                              Smashing Security by Graham Cluley

                              Smashing Security

                              316 Listeners

                              Click Here by Recorded Future News

                              Click Here

                              422 Listeners

                              Darknet Diaries by Jack Rhysider

                              Darknet Diaries

                              8,052 Listeners

                              Cybersecurity Today by Jim Love

                              Cybersecurity Today

                              179 Listeners

                              Hacking Humans by N2K Networks

                              Hacking Humans

                              314 Listeners

                              CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

                              CISO Series Podcast

                              191 Listeners

                              Cybersecurity Headlines by CISO Series

                              Cybersecurity Headlines

                              136 Listeners

                              Cyber Hack by BBC World Service

                              Cyber Hack

                              1,598 Listeners

                              Risky Bulletin by Risky Business Media

                              Risky Bulletin

                              45 Listeners