Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Warns: Medusa Ransomware Steals Data, Disables Security, Encrypts Networks
August 18, 2026
WordPress Sites Hijacked for StopAndProtect Malware C2 Servers
August 18, 2026
Critical MLflow SSRF vulnerability CVE-2023-XXXX exploited in the wild
August 18, 2026
Home/Threats/New EvilTokens Phishing-as-a-Service Steals Microsoft Accounts
Threats

New EvilTokens Phishing-as-a-Service Steals Microsoft Accounts

Key Takeaways A new Phishing-as-a-Service (PaaS) platform named EvilTokens has emerged, offering cybercriminals a sophisticated toolkit to compromise Microsoft 365 accounts. Unlike traditional...

Jennifer sherman
Jennifer sherman
March 31, 2026 4 Min Read
64 0

Key Takeaways

  • A new Phishing-as-a-Service (PaaS) platform named EvilTokens has emerged, offering cybercriminals a sophisticated toolkit to compromise Microsoft 365 accounts.
  • Unlike traditional phishing, EvilTokens exploits Microsoft’s legitimate OAuth 2.0 Device Authorisation Grant flow, tricking users into granting attackers full account access.
  • The platform provides comprehensive tools for affiliates, including phishing templates, email harvesting, and AI-powered automation, with plans to expand to Gmail and Okta.
  • EvilTokens campaigns have impacted organizations globally, particularly in North America and Europe, targeting finance, HR, logistics, and sales roles.
  • Defenders should disable device code authentication where not needed, monitor device code sign-ins, enhance employee training, and use provided YARA rules for detection.

EvilTokens: A New Phishing-as-a-Service Leverages Microsoft Device Code Flow

A novel and highly effective phishing toolkit, dubbed EvilTokens, has surfaced within clandestine cybercrime forums. Launched in early 2026 as a Phishing-as-a-Service (PaaS) offering, this platform provides malicious actors with a ready-to-deploy solution specifically engineered to compromise Microsoft 365 accounts.

Table Of Content

  • Key Takeaways
  • EvilTokens: A New Phishing-as-a-Service Leverages Microsoft Device Code Flow
  • Rapid Adoption and Global Reach
  • How EvilTokens Steals Microsoft Accounts
  • What You Should Do

Distinguishing itself from conventional phishing methods that merely replicate Microsoft login interfaces, EvilTokens employs an insidious tactic: it abuses the legitimate Microsoft device code authentication flow to surreptitiously transfer complete account control to attackers.

Rapid Adoption and Global Reach

EvilTokens made its debut in mid-February 2026 and quickly gained traction among cybercriminals specializing in Business Email Compromise (BEC) and Adversary-in-the-Middle (AitM) attacks.

The platform facilitates its operations through Telegram bots, providing affiliates with a robust suite of tools. This includes customizable phishing page templates, utilities for harvesting email addresses, features for account reconnaissance, an integrated webmail interface, and capabilities powered by artificial intelligence for automation.

The operator, known by the alias “eviltokensadmin,” has publicly stated intentions to extend support for phishing pages targeting Gmail and Okta in the near future.

Researchers at Sekoia’s Threat Detection and Research (TDR) team first identified EvilTokens in March 2026 while actively monitoring cybercrime communities focused on phishing activities. Following an in-depth analysis of the platform’s backend code, TDR analysts confirmed that EvilTokens is the inaugural PaaS known to offer ready-to-use Microsoft device code phishing pages. The team also assessed with high confidence that the kit’s underlying code was likely generated using AI.

Organizations across North America, South America, Europe, the Middle East, Asia, and Oceania have been affected by campaigns linked to EvilTokens. The United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates have experienced the most significant impact. Affiliates have predominantly targeted employees in finance, human resources, logistics, and sales — roles frequently exploited in BEC fraud schemes. By March 23, 2026, researchers had identified over 1,000 domains hosting EvilTokens phishing pages, employing various lures such as fabricated financial reports, meeting invitations, payroll notifications, and shared cloud documents from services like DocuSign, OneDrive, and SharePoint.

How EvilTokens Steals Microsoft Accounts

The fundamental mechanism of EvilTokens relies on the exploitation of Microsoft’s OAuth 2.0 Device Authorisation Grant. This is a legitimate authentication flow designed for devices with limited input capabilities, such as smart televisions or network printers, where a user might enter a short code on a separate, more capable device to complete authentication. EvilTokens subverts this process by impersonating the authenticating device, coercing victims into completing the sign-in on behalf of the attacker.

The attack sequence begins when an attacker initiates a request to Microsoft’s API to generate a unique device code. This code is then presented to the victim through a phishing page or malicious attachment. The victim, under the misconception that they are merely verifying access to a shared document or invoice, navigates to the authentic Microsoft login page and inputs the provided code. Upon successful sign-in by the victim, the attacker’s system instantaneously receives a valid access token and a refresh token. This grants immediate, and potentially long-lasting, unauthorized access to the compromised account.

The acquired access token provides attackers with a window of up to 90 minutes to perform actions such as reading emails, extracting files from OneDrive and SharePoint, and viewing Microsoft Teams conversations. The refresh token, however, poses a far greater threat. It remains valid for 90 days and automatically renews with each use, allowing attackers to maintain persistent, silent access without triggering new login prompts. In more advanced scenarios, EvilTokens can convert these tokens into a Primary Refresh Token (PRT), which enables silent sign-on across all Microsoft 365 applications, completely bypassing password and multi-factor authentication (MFA) requirements.

EvilTokens phishing pages often mimic legitimate services such as Adobe Acrobat Sign, DocuSign, and SharePoint. These pages frequently serve encrypted content using AES-GCM decryption to evade detection by various security tools.

What You Should Do

  • Disable Unnecessary Device Code Authentication: Organizations should leverage Conditional Access policies in Microsoft Entra ID to disable device code authentication flows for users who do not require them.
  • Monitor Device Code Grant Type Sign-ins: Security teams must actively monitor sign-ins initiated via the device code grant type, paying close attention to requests originating from unfamiliar or suspicious locations.
  • Enhance Employee Training: Provide comprehensive employee training on device authentication processes. Educate users about the implications of entering device codes and the risks associated with unexpected requests for such codes. This attack relies heavily on user unawareness.
  • Utilize Detection Tools: Apply the YARA rule published by Sekoia to detect EvilTokens phishing pages within your environment. Additionally, query services like urlscan.io and urlquery using known EvilTokens URL patterns to identify related malicious infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

macOS Sonoma Feature Warns Users of ClickFix Attacks

Next Post

ChatGPT Bug Exposed User Prompts, Sensitive Data

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
JWR Phishing Framework Steals Banking Credentials via WebSocket Control
August 18, 2026
GEEKOM Mini PC Realtek LAN Driver Infected With Asruex Trojan
August 18, 2026
BTMob Fraud-as-a-Service Platform Uses 1,400 Servers for Android Takeovers
August 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us