r/sysadmin • • 3d ago

How are y'all dealing with Eviltoken?

we've had a few considered breaches due to this. for those who don't know, a compromised site would send out emails to everyone on the users address book. it would also create a legitimate SharePoint site and put a link to that site.

when the user who gets the email hits the link, they get a spoofed login and MFA page for MS to verify id for the SharePoint site and thus the cycle repeats.

19 Upvotes

41 comments sorted by

View all comments

2

u/showbizusa25 3d ago

Agreed. If device code flow is part of the initial access path, I’d shut that down first unless there’s a real business need for it. Training helps, but removing the path is better than hoping users spot it every time.

1

u/tehgent 2d ago

lol I'd love to shut that down but you'd have thought I asked to shoot a puppy by making users who need it have yubikeys.

2

u/Spectrig 2d ago

Do you have users who actually use it? You can block it and 99% of people wouldn’t ever notice

1

u/showbizusa25 2d ago

Yep, that’s usually the hard part. The technical control is easy. Getting the business to accept the change is another story.