A Day With Webamon: EvilTokens, and a Long-Running Indian Tax Lure
ID: 0fc37194-4062-4d09-9b6c-aaf1c010702a
STIX ID: report--0fc37194-4062-4d09-9b6c-aaf1c010702a
Threat Score
60/100
This post analyzes two active phishing campaigns: EvilTokens, a phishing-as-a-service that abuses Microsoft's OAuth device-code flow (notably using workers.dev fronting and X-Antibot-Token headers) to harvest credentials/tokens, and a long-running Indian tax impersonation campaign that leverages many short-lived domains (.live/.love) and consolidated ASN infrastructure; the author provides IOCs, timelines, ASN/hosting graphs, and detection queries to track both campaigns.
