Skip to Content

EvilTokens threat hunt stops session theft in seconds

MDR threat cases are real-world stories that demonstrate how Sophos MDR’s AI-native cybersecurity defense system detects, investigates, and responds to active cyberattacks — combining AI speed and expert human judgement to stop threats before they cause damage.

MDR Threat case

EvilTokens threat hunt stops session theft in seconds

Partner: IT Services Provider, New Jersey, US 

Organization: Business consulting firm, 100-200 employees, California, US

Solution: Sophos MDR, Sophos Endpoint, Sophos Email


Adversary activity

An attacker carries out an EvilTokens phishing campaign against a healthcare staffing organization, leading a user to interact with the phishing lure where their Microsoft 365 session token is captured through a legitimate authentication flow. Instead of capturing passwords, EvilTokens steals authenticated Microsoft 365 session tokens, allowing attackers to inherit entire sessions. Although existing Conditional Access controls mitigate some of the potential impact, the attacker is still positioned to exploit the exposed, active session.

Threat detection

Sophos MDR’s Threat Hunting AI agent continuously hunts for hidden threats using the latest intelligence from Sophos X-Ops, actively searching customer environments for attacker tactics, tools, and infrastructure. During a global EvilTokens hunt, Sophos MDR identifies the user account that interacted with the malicious phishing campaign. The finding is automatically escalated, initiating response actions before the compromised session can be leveraged by the attacker. 

Automated response 

Sophos MDR rapidly correlates the known token-theft phishing activity and the exposed Microsoft 365 session to validate the threat. Using direct Microsoft response integrations, the system automatically blocks the user's sign-in and revokes the active session, immediately cutting off attacker access. The time from the threat hunt discovery to containment takes just 116 seconds. 

Human judgment

Automation handles speed and scale, Sophos MDR experts own the outcome. The team reviews findings and works with the customer and partner on clear remediation steps. Building on this organization's controls, Sophos MDR validates the response, recommends a credential reset, and stages additional Conditional Access controls designed to further reduce the risk of future session token theft attacks.