EvilTokens Phishing Kit - POST to /api/device/start on Cloudflare Workers domain initiating Microsoft OAuth Device Code flow
This rule detects network traffic indicative of the 'EvilTokens' phishing kit, specifically targeting Microsoft OAuth Device Code flow. It looks for HTTP POST requests to the '/api/device/start' URI on domains hosted on Cloudflare Workers ('.workers.dev'). This pattern suggests an attempt to initiate a device code phishing attack, where adversaries trick users into entering credentials or codes to grant access to malicious applications.
Suricata

