EvilTokens PhaaS Kit Phishing Related Request - Proxy — Detection Rule

Detects outbound web proxy requests to URLs matching the EvilTokens Phishing-as-a-Service (PhaaS) kit infrastructure. Specifically Cloudflare Workers and Railway.app domains used in OAuth device code authorization phishing attacks. This indicates a user has clicked a phishing link.

Read the full analysis on IntelFusions