Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
EvilTokens Steals Microsoft Sessions, AI Selects New Targets
August 25, 2026
Hackers Use Google Sites to Host Fake OpenAI Codex Download Pages
August 25, 2026
CISA Warns of Exploited Critical Oracle WebLogic, HTTP Server Flaws
August 25, 2026
Home/Threats/EvilTokens Steals Microsoft Sessions, AI Selects New Targets
Threats

EvilTokens Steals Microsoft Sessions, AI Selects New Targets

Key Takeaways EvilTokens is a sophisticated phishing-as-a-service (PhaaS) platform that not only steals Microsoft 365 session tokens but also leverages AI to analyze compromised mailboxes for...

David kimber
David kimber
August 25, 2026 4 Min Read
2 0

Key Takeaways

  • EvilTokens is a sophisticated phishing-as-a-service (PhaaS) platform that not only steals Microsoft 365 session tokens but also leverages AI to analyze compromised mailboxes for high-value targets.
  • The service uses a legitimate Microsoft sign-in process via OAuth device code phishing, making detection challenging as victims authenticate on genuine Microsoft sites.
  • Once a session is compromised, EvilTokens’ AI capabilities analyze email content to identify key contacts, financial transactions, and organizational communication patterns, enabling highly targeted and convincing follow-up fraud.
  • Initial reports indicate widespread impact, with 344 organizations across five countries affected in a 16-day period, and over 1,000 instances of related infrastructure detected.
  • Organizations must implement stricter controls around device code authentication, monitor for unusual account activity post-login, and educate users on the evolving nature of phishing attacks.

A new phishing-as-a-service (PhaaS) platform, dubbed EvilTokens, is revolutionizing how cybercriminals conduct business email compromise (BEC) attacks. Beyond merely stealing Microsoft 365 session tokens, EvilTokens incorporates artificial intelligence to analyze compromised mailboxes, providing attackers with detailed insights to select optimal targets and craft highly convincing fraud schemes.

Table Of Content

  • Key Takeaways
  • EvilTokens Doesn’t Just Steal Microsoft Sessions
  • Device-Code Attacks Demand Tighter Controls
  • What You Should Do

Unlike traditional phishing kits that rely on fake login pages, EvilTokens employs a more insidious method. It initiates a real Microsoft sign-in process, leveraging the OAuth device code flow. Victims are lured to a controlled page where a device code is generated, then redirected to Microsoft’s authentic login portal to approve it. This technique ensures users interact with a genuine Microsoft site, bypassing many conventional phishing detection mechanisms.

Security researchers at Flare said in a report that EvilTokens was first identified in February 2026 and is predominantly advertised and sold via Telegram channels. The platform’s unique selling proposition lies in its combination of efficient session capture with advanced post-compromise analysis, making sophisticated financial fraud accessible even to less experienced affiliates.

The scale of EvilTokens’ operations is significant. One 16-day campaign alone impacted 344 organizations across five countries. Separate investigations have uncovered more than 1,000 search results linked to EvilTokens infrastructure and 66 email attachments designed to lead victims to its phishing pages. These figures underscore the rapid deployment and adoption of this service within the cybercriminal underground.

EvilTokens Doesn’t Just Steal Microsoft Sessions

The critical innovation distinguishing EvilTokens is its post-compromise intelligence gathering. After successfully stealing a session token, the platform systematically scans the victim’s mailbox. It meticulously searches for sensitive information, including invoices, payment requests, ongoing transactions, and historical email exchanges. This deep dive allows the AI to map out an organization’s financial workflows.

EvilTokens identifies key personnel such as suppliers, decision-makers, and individuals authorized to approve payments. Concurrently, it analyzes the typical language, tone, and approval procedures used within the organization. This comprehensive understanding provides attackers with a crucial advantage, allowing them to bypass the guesswork often associated with crafting fraudulent communications.

With this information, the platform’s AI generates summaries of email data and drafts tailored messages that mimic genuine business relationships. Instead of sending generic fake invoices, attackers can target specific, trusted contacts with requests that align perfectly with an organization’s internal communications and financial processes. This significantly lowers the barrier to entry for conducting sophisticated business email compromise (BEC) attacks, intensifying pressure on finance and security teams.

This evolving threat highlights a shift in token theft campaigns. The risk is no longer limited to an intruder passively reading emails. With EvilTokens, a compromised mailbox becomes an active staging ground for identifying subsequent victims and meticulously preparing personalized fraud attempts, all facilitated by an “as-a-service” model.

Device-Code Attacks Demand Tighter Controls

The ingenuity of EvilTokens lies in its ability to circumvent traditional multi-factor authentication (MFA) and password defenses. Victims complete their authentication directly on legitimate Microsoft pages, but in doing so, they unknowingly authorize the attacker’s pre-initiated session. Microsoft then issues valid tokens to this malicious session, granting the attacker full access.

The timing of these attacks is precisely calculated. Microsoft device codes typically have a 15-minute validity period. EvilTokens generates a new code only when a target accesses the phishing page, ensuring the code is fresh and maximizing the attacker’s window to collect the issued tokens before expiration. This makes the authorization process appear routine to the victim while securing the attacker’s access.

What You Should Do

  • Restrict Device Code Authentication: Limit the use of OAuth device code authentication to only essential applications and users. Disable it entirely where it is not a required business function.
  • Enhance Monitoring for Anomalies: Implement robust monitoring for unexpected device code grants, logins from unfamiliar devices or unusual geographic locations, new token issuance, and suspicious consent activities.
  • Shorten Token Lifetimes: Configure shorter session token lifetimes to reduce the window of opportunity for attackers should a token be compromised.
  • Prompt Session Revocation: Establish procedures for immediate session revocation upon detection of any suspicious activity related to token usage.
  • User Education: Educate employees to be highly suspicious of any unexpected device codes, approval prompts, or verification requests, even if they appear to originate from legitimate Microsoft sites. Emphasize that a real login page does not guarantee a request is safe.
  • Post-Login Activity Analysis: Focus detection efforts beyond the initial login. Monitor for unusual post-sign-in activities such as extensive mailbox searches, the creation of new inbox rules, token reuse, unauthorized access to cloud data, or emails sent from a user’s account without their knowledge.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackphishingSecurity

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Hackers Use Google Sites to Host Fake OpenAI Codex Download Pages

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Anthropic Enhances Claude Security with Enterprise-Managed Authentication
August 25, 2026
Minecraft Malware: Top Google Results Led Gamers to Dangerous Downloads
August 25, 2026
Fake GTA 6 Demo Delivers ‘Stealer’ Malware, Steals Passwords and Sessions
August 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us