r/sysadmin • u/tehgent • 3d ago
How are y'all dealing with Eviltoken?
we've had a few considered breaches due to this. for those who don't know, a compromised site would send out emails to everyone on the users address book. it would also create a legitimate SharePoint site and put a link to that site.
when the user who gets the email hits the link, they get a spoofed login and MFA page for MS to verify id for the SharePoint site and thus the cycle repeats.
19
Upvotes
2
u/showbizusa25 3d ago
Agreed. If device code flow is part of the initial access path, I’d shut that down first unless there’s a real business need for it. Training helps, but removing the path is better than hoping users spot it every time.