EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by abusing the OAuth 2.0 Device Authorization Grant flow. Rather than stealing passwords through counterfeit login pages, it tricks victims into entering an attacker-generated Microsoft device code on Microsoft’s legitimate device login portal and completing normal authentication, including MFA. This causes Microsoft to issue access and refresh tokens to the attacker’s session, enabling account takeover without direct credential theft and reducing many traditional phishing indicators.
The platform has been active since at least early 2026 and has been sold through Telegram-based criminal channels on a subscription model. It provides turnkey phishing infrastructure, lure templates, token handling, and post-compromise workflows that lower the barrier to entry for affiliates. Observed lures impersonate common business workflows such as invoices, shared documents, signature requests, voicemail notices, calendar invites, password expiry notices, and SharePoint or OneDrive access requests. Delivery has been observed through phishing emails and malicious document attachments or links, including formats such as PDF, HTML, DOCX, XLSX, and SVG.
EvilTokens is associated with campaigns targeting Microsoft 365 and Entra ID environments globally, with repeated targeting of finance, human resources, logistics, sales, and accounts-payable personnel to support business email compromise and fraud operations. Reported post-compromise capabilities include token refresh, conversion of stolen authentication material into Primary Refresh Tokens for persistence, browser single sign-on hijacking, Outlook Web Access session generation, Microsoft Graph and Azure reconnaissance, and access to email, Teams, SharePoint, and OneDrive data. Operators have used compromised access for mailbox monitoring, data theft, and business email compromise activity, and related ecosystems have shown the ability to create inbox rules and maintain access after password changes.
EvilTokens has also been linked to a broader affiliate ecosystem. ARToken has been assessed as an affiliate panel or closely related offshoot sharing infrastructure, API contracts, deployment patterns, and token-management workflows with EvilTokens, indicating maturation from a phishing kit into a broader service platform for scalable Microsoft 365 intrusion and follow-on abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors query Microsoft’s GetCredentialType endpoint to confirm a targeted email address exists and is active within a tenant, typically 10-15 days before the phishing attempt is launched.
The victim is redirected to the genuine microsoft.com/devicelogin page, pastes the code, and completes their own password and MFA as normal -- unknowingly authorizing the attacker’s session.
EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens... The campaign employs a "ghost phishing" technique...
The phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads...
Impersonating domains observed include patterns such as graph-microsoft[.]com, portal-azure[.]com, office365-login[.]com, and randomized brand-impersonating subdomains such as a7b2-c9d4.office-verify[.]net (domain shadowing).
The victim is redirected to the genuine microsoft.com/devicelogin page, pastes the code, and completes their own password and MFA as normal -- unknowingly authorizing the attacker’s session.
Automatisation des opérations de Business Email Compromise (BEC)
Other observed post-compromise activity: creation of malicious inbox rules for silent mail exfiltration...
Accès complet aux boîtes Outlook ... Surveillance simultanée de plusieurs boîtes compromises par mots-clés
148 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An AI-powered phishing-as-a-service platform referenced as pairing with Jalisco to support real-time OAuth code delivery for phishing operations.
An AI-powered phishing-as-a-service kit used to mirror target branding and support device code phishing campaigns at scale.
A phishing kit used in device code phishing campaigns, reached through multiple redirect and infrastructure hops before presenting the phishing flow.
Commercial phishing platform associated with Microsoft 365 device code phishing and BEC enablement. The content describes it as a commercial PhaaS offering with similar OAuth device authorization, PRT-related endpoints, Cloudflare Workers deployment, and AI/LLM-assisted workflow for scoring mailbox value and automating BEC campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.