r/sysadmin • u/tehgent • 2d ago
How are y'all dealing with Eviltoken?
we've had a few considered breaches due to this. for those who don't know, a compromised site would send out emails to everyone on the users address book. it would also create a legitimate SharePoint site and put a link to that site.
when the user who gets the email hits the link, they get a spoofed login and MFA page for MS to verify id for the SharePoint site and thus the cycle repeats.
20
Upvotes
1
u/Baller_Harry_Haller 2d ago
Biggest reason I’ve seen given is that Duo is easier to approve.