2026 Critical Cloud Identity Detection: Refresh Token Reuse from Anomalous Location or Device
This rule detects the reuse of the same user's refresh token from two different countries within a 15-minute window. This behavior is a strong indicator of token theft or session hijacking, commonly associated with AiTM phishing, infostealer malware, or session cookie extraction, where an adversary uses stolen credentials from a remote location.
YARA-L

