Tech News
← Home  ·  All topics

Microsoft Entra

2 GoKawiil briefs on this topic

Microsoft dismantles EvilTokens phishing service, two arrested in UK

Microsoft has shut down EvilTokens, a subscription-based cybercrime service sold via Telegram that used AI tools to break into Microsoft accounts and mine stolen inboxes for payment details and business contacts. The company said the service compromised roughly 12,000 accounts across 10,000 organizations by abusing Microsoft's device-code sign-in process, and it seized 50 websites and 150 domains via legal action. UK police separately arrested two men suspected of running the operation.

Varonis details TrustSink attack abusing Microsoft Entra external MFA providers

Varonis Threat Labs disclosed a technique called TrustSink in which an attacker with a highly privileged Entra account registers a rogue external MFA provider that inserts a fake password prompt into legitimate login flows, capturing users' plaintext passwords. The rogue provider still returns a valid signed token to Entra, so the sign-in completes normally with no visible error, and resetting a stolen password does not remove the malicious provider from the authentication flow. Varonis says the method could work with any authentication system using this external MFA model but demonstrated it specifically against Microsoft Entra.