
EvilTokens threat hunt stops session theft in seconds
Partner: IT Services Provider, New Jersey, US
Organization: Business consulting firm, 100-200 employees, California, US
Solution: Sophos MDR, Sophos Endpoint, Sophos Email
Adversary activity
An attacker carries out an EvilTokens phishing campaign against a healthcare staffing organization, leading a user to interact with the phishing lure where their Microsoft 365 session token is captured through a legitimate authentication flow. Instead of capturing passwords, EvilTokens steals authenticated Microsoft 365 session tokens, allowing attackers to inherit entire sessions. Although existing Conditional Access controls mitigate some of the potential impact, the attacker is still positioned to exploit the exposed, active session.
Threat detection
Sophos MDR’s Threat Hunting AI agent continuously hunts for hidden threats using the latest intelligence from Sophos X-Ops, actively searching customer environments for attacker tactics, tools, and infrastructure. During a global EvilTokens hunt, Sophos MDR identifies the user account that interacted with the malicious phishing campaign. The finding is automatically escalated, initiating response actions before the compromised session can be leveraged by the attacker.
Automated response
Sophos MDR rapidly correlates the known token-theft phishing activity and the exposed Microsoft 365 session to validate the threat. Using direct Microsoft response integrations, the system automatically blocks the user's sign-in and revokes the active session, immediately cutting off attacker access. The time from the threat hunt discovery to containment takes just 116 seconds.
Human judgment
Automation handles speed and scale, Sophos MDR experts own the outcome. The team reviews findings and works with the customer and partner on clear remediation steps. Building on this organization's controls, Sophos MDR validates the response, recommends a credential reset, and stages additional Conditional Access controls designed to further reduce the risk of future session token theft attacks.