CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

Source: Hackread  ·  Category: Threat Actor & Campaign


CalPhishing campaign exploits Outlook calendar invites and device code phishing to steal Microsoft 365 session tokens and bypass MFA. High relevance: law firm staff heavily dependent on M365; implement conditional access policies and disable device code auth where possible.

→ Read the full article

Read more