Vigyata.AI
Is this your channel?

HUGE AI-powered Microsoft Account phishing campaign

27.2K views· 1,003 likes· 15:00· Apr 9, 2026

🛍️ Products Mentioned (7)

https://jh.live/flare-040826 || Manage threat intelligence and your exposed attack surface with Flare! Try a free trial and see what info is out there: https://jh.live/flare-040826 https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign Learn Cybersecurity and more with Just Hacking Training: https://jh.live/training See what else I'm up to with: https://jh.live/newsletter ℹ️ Affiliates: Learn how to code with CodeCrafters: https://jh.live/codecrafters Host your own VPN with OpenVPN: https://jh.live/openvpn Get Blue Team Training and SOC Analyst Certifications with CyberDefenders: https://jh.live/cyberdefense

About This Video

In this video I break down a huge Microsoft 365 phishing surge we saw recently, centered around a technique called device code phishing. It abuses a real, legitimate Microsoft sign-in flow (device code authentication—think “type this code to sign in on your TV”) and it’s wildly over-permissive. The nasty part is it can effectively “bypass” MFA, because the victim is still completing a genuine Microsoft login—just on behalf of the attacker. What made this campaign stand out is scale and personalization: 340+ organizations worldwide, exploding through March, with lures that weren’t copy-pasted. Each target got their own unique bait, and that’s where AI comes in. I show live lure pages (DocuSign, Adobe Acrobat, construction bids, voicemails, password expiration, meeting invites) and explain how attackers used Railway (a legitimate PaaS) to spin up infrastructure fast—vibe-coded phishing-as-a-service. With reverse proxy setups, they can capture the traffic and steal the token/session secrets needed to take over an account. We also saw heavy use of redirect chains through trusted services (Cisco Secure Email, Trend Micro URL protection, Mimecast) to dodge email security. The coolest part: collaborating with Flare to attribute the activity to “Evil Tokens,” a phishing-as-a-service operation advertising in Telegram. The takeaway is simple: AI is making phishing more targeted and scalable, and defenders need to treat identity as a primary battleground—monitor exposure, hunt for indicators, and harden Microsoft 365 sign-in flows wherever possible.

Frequently Asked Questions

🎬 More from John Hammond