The arrests, executed by Cleveland Police’s Cyber Crime Unit and the Dutch National Police, mark the culmination of a three-year investigation into a phishing tool designed to extract authentication codes and sensitive personal data from victims.
At the heart of the alleged scheme is a tool leveraging device code phishing, a technique that exploits the OAuth device authorization grant flow.
Attackers generate a unique device code-often using tools like TokenTactics trick victims into entering it on a legitimate authentication page, such as Microsoft’s device login portal.
This grants the attacker an access token, bypassing the need for direct password or multi-factor authentication (MFA) interception.
A typical attack sequence involves:
Import-Module C:ToolsTokenTacticsTokenTactics.psd1 Get-AzureToken -Client GraphThe tool reportedly functioned as a bot automated software agent capable of launching thousands of attacks, harvesting one-time passwords (OTP) from SMS via notification listeners, and executing fraudulent transactions across 13 countries.
Investigators estimate the tool was deployed over 28,000 times in two years, compromising accounts and facilitating unauthorized transfers, identity theft, and large-scale money the process of concealing the origins of illicitly obtained funds through complex transactions.
The operation’s technical sophistication included evasion tactics, bot automation, and exploitation of legitimate authentication flows, making detection challenging for both users and security systems.
Today’s arrests were coordinated with support from the North East Regional Organised Crime Unit (NEROCU), the National Crime Agency (NCA), Europol, and hosting providers, who assisted in taking down the malicious platform.
Detective Sergeant Kevin Carter emphasized the unprecedented scale of the investigation and the critical role of international collaboration in disrupting the network.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post JokerOTP Platform Behind 28,000+ Phishing Attacks Dismantled appeared first on Cyber Security News.
DEKALB COUNTY, Ind. (WOWO) — A 30-year-old man from Columbia City was killed Monday morning…
MARION COUNTY, Ind. (WOWO) — Indiana Conservation Officers are investigating after a woman’s body was…
U.S. Agriculture Secretary Brooke Rollins, speaking at a Future Farmers of America event Aug. 18,…
Take-Two CEO Strauss Zelnick has suggested that Elon Musk might want to watch out for…
Heated Rivalry show creator, writer, and director, Jacob Tierney, revealed new details for Season 2…
Moon Knight star Oscar Isaac has teased the possibility that his hooded hero could return…
This website uses cookies.