New EvilTokens Phishing-as-a-Service Steals Microsoft Accounts
Key Takeaways A new Phishing-as-a-Service (PaaS) platform named EvilTokens has emerged, offering cybercriminals a sophisticated toolkit to compromise Microsoft 365 accounts. Unlike traditional...
Key Takeaways
- A new Phishing-as-a-Service (PaaS) platform named EvilTokens has emerged, offering cybercriminals a sophisticated toolkit to compromise Microsoft 365 accounts.
- Unlike traditional phishing, EvilTokens exploits Microsoft’s legitimate OAuth 2.0 Device Authorisation Grant flow, tricking users into granting attackers full account access.
- The platform provides comprehensive tools for affiliates, including phishing templates, email harvesting, and AI-powered automation, with plans to expand to Gmail and Okta.
- EvilTokens campaigns have impacted organizations globally, particularly in North America and Europe, targeting finance, HR, logistics, and sales roles.
- Defenders should disable device code authentication where not needed, monitor device code sign-ins, enhance employee training, and use provided YARA rules for detection.
EvilTokens: A New Phishing-as-a-Service Leverages Microsoft Device Code Flow
A novel and highly effective phishing toolkit, dubbed EvilTokens, has surfaced within clandestine cybercrime forums. Launched in early 2026 as a Phishing-as-a-Service (PaaS) offering, this platform provides malicious actors with a ready-to-deploy solution specifically engineered to compromise Microsoft 365 accounts.
Table Of Content
Distinguishing itself from conventional phishing methods that merely replicate Microsoft login interfaces, EvilTokens employs an insidious tactic: it abuses the legitimate Microsoft device code authentication flow to surreptitiously transfer complete account control to attackers.
Rapid Adoption and Global Reach
EvilTokens made its debut in mid-February 2026 and quickly gained traction among cybercriminals specializing in Business Email Compromise (BEC) and Adversary-in-the-Middle (AitM) attacks.
The platform facilitates its operations through Telegram bots, providing affiliates with a robust suite of tools. This includes customizable phishing page templates, utilities for harvesting email addresses, features for account reconnaissance, an integrated webmail interface, and capabilities powered by artificial intelligence for automation.
The operator, known by the alias “eviltokensadmin,” has publicly stated intentions to extend support for phishing pages targeting Gmail and Okta in the near future.
Researchers at Sekoia’s Threat Detection and Research (TDR) team first identified EvilTokens in March 2026 while actively monitoring cybercrime communities focused on phishing activities. Following an in-depth analysis of the platform’s backend code, TDR analysts confirmed that EvilTokens is the inaugural PaaS known to offer ready-to-use Microsoft device code phishing pages. The team also assessed with high confidence that the kit’s underlying code was likely generated using AI.
Organizations across North America, South America, Europe, the Middle East, Asia, and Oceania have been affected by campaigns linked to EvilTokens. The United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates have experienced the most significant impact. Affiliates have predominantly targeted employees in finance, human resources, logistics, and sales — roles frequently exploited in BEC fraud schemes. By March 23, 2026, researchers had identified over 1,000 domains hosting EvilTokens phishing pages, employing various lures such as fabricated financial reports, meeting invitations, payroll notifications, and shared cloud documents from services like DocuSign, OneDrive, and SharePoint.
How EvilTokens Steals Microsoft Accounts
The fundamental mechanism of EvilTokens relies on the exploitation of Microsoft’s OAuth 2.0 Device Authorisation Grant. This is a legitimate authentication flow designed for devices with limited input capabilities, such as smart televisions or network printers, where a user might enter a short code on a separate, more capable device to complete authentication. EvilTokens subverts this process by impersonating the authenticating device, coercing victims into completing the sign-in on behalf of the attacker.
The attack sequence begins when an attacker initiates a request to Microsoft’s API to generate a unique device code. This code is then presented to the victim through a phishing page or malicious attachment. The victim, under the misconception that they are merely verifying access to a shared document or invoice, navigates to the authentic Microsoft login page and inputs the provided code. Upon successful sign-in by the victim, the attacker’s system instantaneously receives a valid access token and a refresh token. This grants immediate, and potentially long-lasting, unauthorized access to the compromised account.
The acquired access token provides attackers with a window of up to 90 minutes to perform actions such as reading emails, extracting files from OneDrive and SharePoint, and viewing Microsoft Teams conversations. The refresh token, however, poses a far greater threat. It remains valid for 90 days and automatically renews with each use, allowing attackers to maintain persistent, silent access without triggering new login prompts. In more advanced scenarios, EvilTokens can convert these tokens into a Primary Refresh Token (PRT), which enables silent sign-on across all Microsoft 365 applications, completely bypassing password and multi-factor authentication (MFA) requirements.
EvilTokens phishing pages often mimic legitimate services such as Adobe Acrobat Sign, DocuSign, and SharePoint. These pages frequently serve encrypted content using AES-GCM decryption to evade detection by various security tools.
What You Should Do
- Disable Unnecessary Device Code Authentication: Organizations should leverage Conditional Access policies in Microsoft Entra ID to disable device code authentication flows for users who do not require them.
- Monitor Device Code Grant Type Sign-ins: Security teams must actively monitor sign-ins initiated via the device code grant type, paying close attention to requests originating from unfamiliar or suspicious locations.
- Enhance Employee Training: Provide comprehensive employee training on device authentication processes. Educate users about the implications of entering device codes and the risks associated with unexpected requests for such codes. This attack relies heavily on user unawareness.
- Utilize Detection Tools: Apply the YARA rule published by Sekoia to detect EvilTokens phishing pages within your environment. Additionally, query services like urlscan.io and urlquery using known EvilTokens URL patterns to identify related malicious infrastructure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.