Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 4, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
MITRE ATT&CK
Reporting
Researchers reported that the EvilTokens phishing-as-a-service platform is being used to steal Microsoft 365 access tokens through OAuth device code phishing, with one campaign abusing free Notion accounts and malicious PDFs to lure victims. In the activity tracked as Doubloon Dredger, attackers sent legitimate-looking Notion document-sharing notifications from compromised accounts impersonating senior executives, then redirected targets to phishing pages disguised as Adobe Acrobat authentication prompts. Victims were instructed to enter a verification code on Microsoft’s legitimate sign-in or device code page, allowing Microsoft to issue authorization tokens directly to the attackers without requiring password theft. The operation has targeted organizations in manufacturing, telecommunications, retail, healthcare, and logistics, and researchers said EvilTokens has been active since at least February 2026 and is marketed largely through Telegram. Flare said the platform goes beyond session theft by analyzing compromised mailboxes, using AI to summarize content and identify likely fraud opportunities, and helping operators craft tailored business email compromise messages based on real payment workflows and relationships. Reported activity included a 16-day wave affecting 344 organizations across five countries, while separate research found more than 1,000 infrastructure-related search results and 66 email attachments leading to EvilTokens pages; defenders were urged to restrict or disable device-code authentication where possible and monitor for anomalous token grants, inbox rule creation, mailbox searches, token reuse, and suspicious outbound email.
German authorities, working with the United States and Indonesia, dismantled the core infrastructure of Kratos, a phishing-as-a-service platform described as one of the world’s most widely used criminal phishing services. Investigators seized or neutralized more than 200 servers and arrested the alleged developer and technical administrator in Indonesia, a move authorities said rendered the service inoperable. The action was carried out under Operation Olympus Blade, and the FBI took control of Kratos-linked domains to support follow-on investigation and customer identification. Kratos supplied Microsoft-themed phishing pages designed to steal credentials and session cookies, allowing attackers to hijack accounts and bypass multi-factor authentication. Authorities said the platform was used by roughly 1,800 criminal customers to launch about 15,000 phishing campaigns per month against victims in at least 35 countries, with organizations in the United States and Europe—particularly in manufacturing, retail, healthcare, and education—among the main targets. Investigators estimate the operation generated more than €300,000 since 2024.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.