The Illicit Consent Grant Part 2: Device-Code Phishing and the AI PhaaS Wave
Part 1 showed the illicit consent grant done by hand. Part 2 shows its close cousin — device-code phishing — now sold as a ready-made kit, with AI writing the lures and reading the stolen mailbox. We analyze two Phishing-as-a-Service platforms, EvilTokens and the FBI-flagged Kali365, walk the device-code attack through the same three phases from Part 1, and share what a sandboxed reconstruction taught us — then map detection and mitigation to the SlashID identity layer.
SlashID TeamThreat Intelligence