EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts through abuse of Microsoft’s OAuth 2.0 Device Authorization Grant, commonly known as device code phishing. Emerging in early 2026, it is associated with large-scale campaigns that obtained Microsoft 365 access and refresh tokens without presenting counterfeit login pages or directly stealing passwords. Victims are instead lured into completing authentication on Microsoft’s legitimate device login page, after which tokens are issued to attacker-controlled clients, enabling practical bypass of standard MFA protections. The platform has been used at scale against hundreds of organizations across multiple countries and is closely associated with downstream business email compromise activity. Reported lure themes include document-sharing requests, meeting invitations, voicemail notifications, invoices, bids, and other business workflow pretexts tailored to the victim’s role. EvilTokens operators and affiliates have used trusted cloud and serverless infrastructure, multi-stage redirect chains, CAPTCHA and anti-bot controls, and cloud-hosted landing pages to reduce detection and obscure delivery infrastructure. EvilTokens provides affiliates with a centralized operational environment for token theft and post-compromise exploitation. Documented capabilities include token capture and management, access to Outlook and other Microsoft 365 services, persistence through Primary Refresh Token acquisition, Microsoft Graph reconnaissance, mailbox review, and collaborative administration features suited to organized BEC workflows. Reporting also describes a custom browser component for managing multiple compromised Microsoft 365 sessions simultaneously. A notable aspect of EvilTokens is its reported integration of AI-assisted post-compromise workflows. These capabilities have been described as supporting analysis of stolen mailbox content, identification of financially relevant conversations, translation, and drafting of follow-on impersonation or fraud messages, further lowering the barrier to entry for BEC-focused operators. EvilTokens is part of a broader ecosystem of Microsoft 365-focused phishing services and has been linked to affiliate or closely related tooling such as ARToken. ARToken has been described as sharing EvilTokens device-code workflow patterns, token persistence mechanisms, and broader BEC-oriented operational features. EvilTokens has also been discussed alongside other phishing-as-a-service offerings such as Tycoon2FA, Kratos, Kali365, Ghost Hub, and Cyb3r as device code phishing became increasingly commoditized in 2026. The actor’s dominant activity is financially motivated account takeover and fraud enablement, especially business email compromise, rather than espionage or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Device-code phishing service targeting Microsoft 365 users by tricking victims into authorizing attacker-controlled sessions through Microsoft's legitimate OAuth device flow, yielding access and refresh tokens.
Phishing-as-a-Service platform abusing Microsoft OAuth 2.0 Device Authorization Grant to trick victims into authorizing attacker-controlled clients, yielding access and refresh tokens without stealing passwords directly.
Running a phishing-as-a-service operation that abuses Microsoft OAuth device-code flow to trick victims into authorizing attacker-controlled clients, yielding access and refresh tokens for ongoing Microsoft 365 access and downstream business email compromise.
A phishing-as-a-service platform attributed to earlier device code phishing waves linked to Railway, used for Microsoft 365 token-focused phishing operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.