EvilTokens Steals Microsoft Sessions, AI Selects New Targets
Key Takeaways EvilTokens is a sophisticated phishing-as-a-service (PhaaS) platform that not only steals Microsoft 365 session tokens but also leverages AI to analyze compromised mailboxes for...
Key Takeaways
- EvilTokens is a sophisticated phishing-as-a-service (PhaaS) platform that not only steals Microsoft 365 session tokens but also leverages AI to analyze compromised mailboxes for high-value targets.
- The service uses a legitimate Microsoft sign-in process via OAuth device code phishing, making detection challenging as victims authenticate on genuine Microsoft sites.
- Once a session is compromised, EvilTokens’ AI capabilities analyze email content to identify key contacts, financial transactions, and organizational communication patterns, enabling highly targeted and convincing follow-up fraud.
- Initial reports indicate widespread impact, with 344 organizations across five countries affected in a 16-day period, and over 1,000 instances of related infrastructure detected.
- Organizations must implement stricter controls around device code authentication, monitor for unusual account activity post-login, and educate users on the evolving nature of phishing attacks.
A new phishing-as-a-service (PhaaS) platform, dubbed EvilTokens, is revolutionizing how cybercriminals conduct business email compromise (BEC) attacks. Beyond merely stealing Microsoft 365 session tokens, EvilTokens incorporates artificial intelligence to analyze compromised mailboxes, providing attackers with detailed insights to select optimal targets and craft highly convincing fraud schemes.
Table Of Content
Unlike traditional phishing kits that rely on fake login pages, EvilTokens employs a more insidious method. It initiates a real Microsoft sign-in process, leveraging the OAuth device code flow. Victims are lured to a controlled page where a device code is generated, then redirected to Microsoft’s authentic login portal to approve it. This technique ensures users interact with a genuine Microsoft site, bypassing many conventional phishing detection mechanisms.
Security researchers at Flare said in a report that EvilTokens was first identified in February 2026 and is predominantly advertised and sold via Telegram channels. The platform’s unique selling proposition lies in its combination of efficient session capture with advanced post-compromise analysis, making sophisticated financial fraud accessible even to less experienced affiliates.
The scale of EvilTokens’ operations is significant. One 16-day campaign alone impacted 344 organizations across five countries. Separate investigations have uncovered more than 1,000 search results linked to EvilTokens infrastructure and 66 email attachments designed to lead victims to its phishing pages. These figures underscore the rapid deployment and adoption of this service within the cybercriminal underground.
EvilTokens Doesn’t Just Steal Microsoft Sessions
The critical innovation distinguishing EvilTokens is its post-compromise intelligence gathering. After successfully stealing a session token, the platform systematically scans the victim’s mailbox. It meticulously searches for sensitive information, including invoices, payment requests, ongoing transactions, and historical email exchanges. This deep dive allows the AI to map out an organization’s financial workflows.
EvilTokens identifies key personnel such as suppliers, decision-makers, and individuals authorized to approve payments. Concurrently, it analyzes the typical language, tone, and approval procedures used within the organization. This comprehensive understanding provides attackers with a crucial advantage, allowing them to bypass the guesswork often associated with crafting fraudulent communications.
With this information, the platform’s AI generates summaries of email data and drafts tailored messages that mimic genuine business relationships. Instead of sending generic fake invoices, attackers can target specific, trusted contacts with requests that align perfectly with an organization’s internal communications and financial processes. This significantly lowers the barrier to entry for conducting sophisticated business email compromise (BEC) attacks, intensifying pressure on finance and security teams.
This evolving threat highlights a shift in token theft campaigns. The risk is no longer limited to an intruder passively reading emails. With EvilTokens, a compromised mailbox becomes an active staging ground for identifying subsequent victims and meticulously preparing personalized fraud attempts, all facilitated by an “as-a-service” model.
Device-Code Attacks Demand Tighter Controls
The ingenuity of EvilTokens lies in its ability to circumvent traditional multi-factor authentication (MFA) and password defenses. Victims complete their authentication directly on legitimate Microsoft pages, but in doing so, they unknowingly authorize the attacker’s pre-initiated session. Microsoft then issues valid tokens to this malicious session, granting the attacker full access.
The timing of these attacks is precisely calculated. Microsoft device codes typically have a 15-minute validity period. EvilTokens generates a new code only when a target accesses the phishing page, ensuring the code is fresh and maximizing the attacker’s window to collect the issued tokens before expiration. This makes the authorization process appear routine to the victim while securing the attacker’s access.
What You Should Do
- Restrict Device Code Authentication: Limit the use of OAuth device code authentication to only essential applications and users. Disable it entirely where it is not a required business function.
- Enhance Monitoring for Anomalies: Implement robust monitoring for unexpected device code grants, logins from unfamiliar devices or unusual geographic locations, new token issuance, and suspicious consent activities.
- Shorten Token Lifetimes: Configure shorter session token lifetimes to reduce the window of opportunity for attackers should a token be compromised.
- Prompt Session Revocation: Establish procedures for immediate session revocation upon detection of any suspicious activity related to token usage.
- User Education: Educate employees to be highly suspicious of any unexpected device codes, approval prompts, or verification requests, even if they appear to originate from legitimate Microsoft sites. Emphasize that a real login page does not guarantee a request is safe.
- Post-Login Activity Analysis: Focus detection efforts beyond the initial login. Monitor for unusual post-sign-in activities such as extensive mailbox searches, the creation of new inbox rules, token reuse, unauthorized access to cloud data, or emails sent from a user’s account without their knowledge.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.