EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 Device Authorization Grant flow. Rather than harvesting passwords through counterfeit login pages, it tricks victims into entering an attacker-generated device code on Microsoft’s legitimate device login portal and completing normal authentication, including multifactor authentication. This causes Microsoft to issue access and refresh tokens to the attacker-controlled session, enabling account takeover without direct credential theft.
The platform emerged in early 2026 and was rapidly adopted by cybercriminal operators conducting account takeover and business email compromise activity. It has been associated with campaigns targeting organizations worldwide, with repeated focus on finance, human resources, logistics, sales, accounts payable, and other business functions that provide access to payments, invoices, internal communications, and sensitive documents. Observed lure themes include invoices, shared documents, SharePoint access requests, voicemail notifications, calendar invites, password expiry notices, and document-signature workflows.
EvilTokens is notable for industrializing device code phishing at scale. Reported capabilities include automated lure generation, real-time device-code handling, token polling, token refresh, and post-compromise operations. Analysis of related infrastructure and backend behavior indicates support for converting stolen authentication material into more persistent access, including abuse of Primary Refresh Tokens, browser single sign-on cookie generation, Outlook Web Access session generation, Microsoft Graph reconnaissance, Azure enumeration, and Telegram-based operator notifications. The ecosystem has also been linked to Cloudflare Workers-hosted phishing infrastructure and anti-analysis or anti-bot mechanisms intended to reduce detection and hinder automated scanning.
The platform has been tied to broader phishing and business email compromise workflows in which operators use compromised Microsoft 365 access to read mailboxes, access SharePoint and OneDrive content, monitor communications, and support fraud operations. Reporting also links EvilTokens to affiliate or closely related panels such as ARToken, which share infrastructure, API patterns, deployment models, and post-compromise tradecraft. EvilTokens is widely regarded as a significant evolution in phishing operations because it removes many traditional phishing indicators, survives password resets when token persistence is established, and lowers the barrier to entry for large-scale token-centric compromise of Microsoft cloud environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors query Microsoft’s GetCredentialType endpoint to confirm a targeted email address exists and is active within a tenant, typically 10-15 days before the phishing attempt is launched.
If they entered the code and completed authentication, the attacker-controlled client could receive OAuth tokens in the background. That has an important consequence for incident response. Resetting the user's password may not be enough if a refresh token has already been issued.
MITRE ATT&CK Mapping Technique ID Technique Applies To T1078.004 Valid Accounts: Cloud Accounts All three (post-compromise)
If they entered the code and completed authentication, the attacker-controlled client could receive OAuth tokens in the background. That has an important consequence for incident response. Resetting the user's password may not be enough if a refresh token has already been issued.
If they entered the code and completed authentication, the attacker-controlled client could receive OAuth tokens in the background. That has an important consequence for incident response. Resetting the user's password may not be enough if a refresh token has already been issued.
The phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads...
Impersonating domains observed include patterns such as graph-microsoft[.]com, portal-azure[.]com, office365-login[.]com, and randomized brand-impersonating subdomains such as a7b2-c9d4.office-verify[.]net (domain shadowing).
If they entered the code and completed authentication, the attacker-controlled client could receive OAuth tokens in the background. That has an important consequence for incident response. Resetting the user's password may not be enough if a refresh token has already been issued.
MITRE ATT&CK Mapping Technique ID Technique Applies To T1078.004 Valid Accounts: Cloud Accounts All three (post-compromise)
If the victim approves the request, the attacker receives access and refresh tokens without directly capturing the password. | EvilTokens abuses Microsoft’s legitimate OAuth Device Authorization Grant rather than relying on a conventional credential-harvesting page.
Automatisation des opérations de Business Email Compromise (BEC)
MITRE ATT&CK Mapping Technique ID Technique Applies To T1114 Email Collection (post-access BEC) EvilTokens
Accès complet aux boîtes Outlook ... Surveillance simultanée de plusieurs boîtes compromises par mots-clés
Other observed post-compromise activity: creation of malicious inbox rules for silent mail exfiltration...
175 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An adversary-in-the-middle phishing kit used to proxy authentication flows and capture session material; mentioned as a separate downstream toolkit seen in similar redirect chains.
An AI-powered phishing-as-a-service platform referenced as pairing with Jalisco to support real-time OAuth code delivery for phishing operations.
An AI-powered phishing-as-a-service kit used to mirror target branding and support device code phishing campaigns at scale.
A phishing kit used in device code phishing campaigns, reached through multiple redirect and infrastructure hops before presenting the phishing flow.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.