Researchers identified EvilTokens as a new phishing-as-a-service platform built to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate OAuth 2.0 device code authentication flow. Sold and operated through Telegram bots, the service gives affiliates phishing templates, email harvesting and reconnaissance features, automated Microsoft API interactions, webmail access, and mailbox triage capabilities. Victims are lured into entering attacker-supplied device codes on Microsoft’s real login page, allowing attackers to capture access and refresh tokens—and in some cases a Primary Refresh Token—without stealing passwords or directly defeating MFA.
Security teams linked a sharp rise in device code phishing to EvilTokens, describing it as the first known turnkey PhaaS offering dedicated Microsoft device code phishing pages and warning that it lowers the barrier for low-skill operators. More than 1,000 phishing domains were observed by late March, with campaigns affecting organizations worldwide and notable activity in the United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates; finance, HR, and transportation/logistics staff were highlighted as frequent targets. Researchers from Sekoia and Mnemonic urged defenders to disable or restrict unnecessary device code flows in Microsoft Entra ID, monitor device code grant sign-ins for anomalies, train users on device authentication abuse, and revoke refresh tokens when compromise is suspected.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-01, Cisco Talos published an analysis of ARToken, a phishing-as-a-service operator panel it linked closely to the EvilTokens ecosystem through shared infrastructure patterns, identical API contracts, and matching Primary Refresh Token persistence workflows. Talos said the platform supports Microsoft 365 device code phishing and extensive post-compromise BEC operations, including token management, email access, inbox rule manipulation, SharePoint or OneDrive actions, and advanced anti-analysis protections.
On 2026-04-04, Push Security reported that device code phishing attacks abusing OAuth 2.0 Device Authorization Grant had increased 37.5 times in 2026. The researchers said EvilTokens was a major driver but identified at least 11 phishing kits using SaaS-themed lures, anti-bot protections, and cloud-hosted infrastructure, indicating broader criminal adoption of the technique.
By 2026-04-01, Sekoia reported that EvilTokens was under active development and that its author planned to add phishing pages targeting Gmail and Okta. This marked an expansion of the platform beyond Microsoft 365-focused device code phishing.
On 2026-03-31, public reports disclosed EvilTokens as a new phishing-as-a-service platform and warned of a notable increase in Microsoft 365 device code phishing tied to the toolkit. The reporting also shared mitigations such as restricting device code flows, monitoring sign-ins, and revoking refresh tokens after suspected compromise.
By 2026-03-23, researchers had observed more than 1,000 phishing domains associated with EvilTokens. Reported targeting included organizations in the United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates.
In March 2026, Sekoia's Threat Detection and Research team identified EvilTokens and, together with Mnemonic, assessed that it was helping scale device code phishing into a broader threat. Sekoia also assessed with high confidence that the platform's backend code was likely AI-generated.
By March 2026, EvilTokens was being operated through Telegram bots and used in campaigns targeting organizations worldwide, with tooling for phishing templates, reconnaissance, webmail access, and automation. The activity was linked to increased device code phishing against Microsoft 365 users, particularly affecting sectors such as finance, HR, and transportation/logistics.
In early 2026, EvilTokens emerged as a phishing-as-a-service platform built to hijack Microsoft 365 accounts by abusing Microsoft's legitimate OAuth 2.0 device code authentication flow. Researchers described it as the first known turnkey PhaaS offering dedicated Microsoft device code phishing pages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcesekoia.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.