NOIRLEGACY GROUP is a cybercriminal brand associated with phishing-as-a-service activity targeting Microsoft 365 accounts. It has been linked to the promotion of EvilTokens, a service that supports Office 365-focused phishing operations and related email-delivery workflows. Activity associated with this ecosystem has been observed at scale against organizations in multiple countries, using Microsoft’s legitimate OAuth device authorization flow to trick victims into entering attacker-supplied device codes on authentic Microsoft login pages. This technique enables theft of access and refresh tokens and can effectively bypass the practical protection normally provided by multi-factor authentication because the victim completes a legitimate authentication flow. The operation has been associated with cloud-hosted infrastructure used for token harvesting and with phishing lures themed around business documents, electronic signatures, voicemail notifications, and employee benefits. Reported EvilTokens capabilities include phishing link generation, SMTP-based delivery, AI-assisted lure customization, and workflows intended to identify sensitive emails for fraud or data theft. The service has also been described as using open-redirect abuse to obscure phishing destinations and as maintaining ongoing customer support, consistent with a commercialized criminal service model. Based on the available facts, NOIRLEGACY GROUP is best characterized as part of a financially motivated cybercrime ecosystem enabling credential and token theft, post-compromise access, and data exfiltration opportunities against enterprise cloud tenants. Attribution beyond its role in advertising and supporting the phishing service is currently not available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.