EvilTokens is a phishing-as-a-service kit designed to compromise Microsoft 365 accounts through abuse of the OAuth 2.0 Device Authorization Grant flow. It presents victims with attacker-generated device codes and directs them to complete authentication, including MFA, on legitimate Microsoft sign-in surfaces. Once the victim authorizes the attacker-controlled device session, operators obtain OAuth access and refresh tokens without collecting the victim’s password. The resulting access can be used to access Microsoft 365 email, Teams, SharePoint, and OneDrive; conduct mailbox monitoring and data theft; and support business email compromise. EvilTokens has been active since at least February 2026, is marketed through Telegram-based channels, and has been used with invoice, document-sharing, calendar, and SharePoint-themed lures. Campaigns have targeted organizations across multiple countries, particularly personnel in finance, HR, logistics, and sales functions. The EvilTokens ecosystem uses phishing infrastructure hosted through legitimate cloud and edge services and has technical links to the ARToken affiliate platform. Device-code phishing evades password-focused defenses because the victim completes legitimate authentication and grants tokens directly to the attacker session.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A “Review and Sign” button then redirected the victim to an EvilTokens device code harvesting page disguised as an Adobe Acrobat document-sharing authentication screen.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors query Microsoft’s GetCredentialType endpoint to confirm a targeted email address exists and is active within a tenant, typically 10-15 days before the phishing attempt is launched.
“Validation of active Microsoft 365 accounts and tenants prior to phishing delivery.”
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
MITRE ATT&CK Mapping Technique ID Technique Applies To T1078.004 Valid Accounts: Cloud Accounts All three (post-compromise)
« L’attaquant génère un code de périphérique [...] le transmet à la victime via phishing. »
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
The phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads...
The actual payload - the redirect URL - is never present in plaintext anywhere in the file. It is decrypted via AES-256-GCM with the threat actor supplied password.
“Abuse of Microsoft’s legitimate authentication portal to appear trustworthy to victims.”
« [Le] device code phishing [est] une technique d’usurpation de compte exploitant le flux OAuth 2.0 Device Authorization Grant. »
“Abuse of OAuth Device Code Authentication to obtain access and refresh tokens.”
MITRE ATT&CK Mapping Technique ID Technique Applies To T1114 Email Collection (post-access BEC) EvilTokens
Other observed post-compromise activity: creation of malicious inbox rules for silent mail exfiltration...
189 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing service mentioned only as a comparison for techniques used by GhostCode.
Referenced only as a prior example of a phishing kit using AES-GCM-gated HTML attachments; the content does not describe EvilTokens as participating in the GhostCode campaign.
Kit de phishing-as-a-service pour le device-code phishing OAuth 2.0. Il génère et transmet des device codes afin de récupérer les jetons d’accès et de rafraîchissement après l’authentification de la victime. Il utilise notamment des frontends Cloudflare Workers et des mécanismes anti-bot, de redirection et de vérification CAPTCHA.
Referenced only as a comparable phishing kit focused on stealing session tokens or OAuth access tokens.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.