EvilTokens is an AI-enabled phishing-as-a-service platform targeting Microsoft 365 accounts. First observed in February 2026, it was developed and supported by the cybercriminal actor Microsoft tracks as Storm-2992. The service provides phishing templates, landing pages, campaign management, victim tracking, and automated post-compromise workflows to facilitate account takeover and business email compromise.
EvilTokens abuses the legitimate OAuth 2.0 Device Authorization Grant. Its phishing pages generate live Microsoft device codes and persuade victims to enter them into Microsoft's genuine sign-in portal. Victims authenticate normally, potentially completing multifactor authentication, but authorize an attacker-controlled session. Automated polling then obtains access and refresh tokens without directly collecting the victim's password. Operators use these tokens to access mailboxes, exfiltrate email, send messages from compromised accounts, and create malicious inbox rules. Some register attacker-controlled devices and obtain Primary Refresh Tokens to maintain access.
The platform uses Microsoft Graph and AI-assisted mailbox analysis to map organizational relationships, identify executives and payment approvers, locate invoices and wire-transfer discussions, and prepare targeted fraud messages. Its AI features also summarize and translate correspondence. Delivery commonly involves invoice, shared-document, signature-request, and voicemail lures, using email links and PDF or HTML attachments. Multi-stage redirects, fake verification challenges, bot filtering, and legitimate cloud-hosting infrastructure help conceal phishing destinations and evade inspection.
EvilTokens campaigns have affected organizations worldwide, including financial services, construction, real estate, healthcare, education, manufacturing, retail, and logistics. Microsoft linked the platform to more than 12,000 compromised mailboxes across over 10,000 organizations. In September 2026, Microsoft and partners coordinated a court-authorized disruption that seized 50 websites and disabled more than 150 associated domains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In September of this year Microsoft took down EvilTokens (attributed to Storm-2992) which had compromised more than 12,000 mailboxes across more than 10,000 organisations.
A “Review and Sign” button then redirected the victim to an EvilTokens device code harvesting page disguised as an Adobe Acrobat document-sharing authentication screen.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Device code phishing rose 1,380%... A single phishing-as-a-service kit, EvilTokens, hit 344 organisations across five countries in 16 days using only legitimate infrastructure.
To bypass protections, platform operators used PDF and HTML attachments; subscribers also had access to phishing templates impersonating Microsoft, e-signature services, file-sharing services, voicemail, and other corporate services.
“Operators used ... device registration and token-refresh mechanisms to maintain access.”
“Operators used ... device registration and token-refresh mechanisms to maintain access.”
“The attacker’s waiting device receives authentication tokens. Those tokens act as digital passes, allowing the attacker to access the victim’s account without knowing their password.”
“Its chatbot could analyse compromised inboxes, identify employees authorised to make payments and map trusted relationships ... [and] search for invoices, wire-transfer discussions and executive correspondence.”
190 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Device-code phishing operation or toolkit attributed to Storm-2992. The content reports more than 12,000 compromised mailboxes across more than 10,000 organizations before Microsoft's September 2026 takedown.
A criminal phishing service targeting Microsoft 365 accounts through impersonated Microsoft authentication and device-code phishing. It supports customized messages, generation of deceptive login codes, and automated actions after account compromise. The content describes a phishing service rather than an endpoint malware binary.
Phishing-as-a-Service platform that abuses OAuth 2.0 Device Authorization Grant (Device Code Flow) to obtain Microsoft-account access and refresh tokens without stealing the victim's password. After compromise, it uses Microsoft Graph and AI tools to analyze mailboxes, identify payment workflows and trusted contacts, and facilitate business-email-compromise phishing.
A phishing-as-a-service kit that abuses Microsoft device-code authentication. It generates device codes and persuades victims to approve attacker-initiated sign-ins at the legitimate Microsoft portal; the attacker then receives access tokens without obtaining the victim's password. Operators use compromised mailboxes for email discovery, relationship mapping, targeted payment fraud, inbox-rule persistence, and device registration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.