Three phishing-as-a-service platforms—Sneaky 2FA, EvilTokens, and EvilProxy—are targeting U.S. organizations to steal Microsoft 365 credentials and authenticated access by capturing session cookies or OAuth tokens after users complete legitimate sign-ins. The kits use different methods, including adversary-in-the-middle session hijacking, abuse of Microsoft’s OAuth 2.0 device authorization flow, and reverse-proxy credential relay, allowing attackers to gain access without breaking MFA cryptographically. Researchers said EvilTokens, which emerged in 2026, has already been linked to compromises at more than 340 Microsoft 365 organizations across at least seven countries, while EvilProxy has been used in campaigns against executives and managers at more than 100 organizations.
The campaigns show that standard MFA does not stop phishing when attackers steal the resulting authenticated session artifact instead of the password alone. Sneaky 2FA reportedly uses CAPTCHA gates, IP filtering, and cloned Microsoft login pages to evade detection, while the broader activity has created detection opportunities around impossible device-shift patterns, anomalous token use, and suspicious device-code prompts. Defenders are being urged to deploy phishing-resistant MFA such as FIDO2/WebAuthn, restrict or disable unnecessary device-code authentication in Entra ID, and closely monitor Microsoft 365 environments for unexpected MFA prompts and token abuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
EvilTokens emerged around mid-February 2026, abusing Microsoft's OAuth device authorization flow to obtain access and refresh tokens from victims who complete legitimate sign-in and MFA.
Push Security and Sekoia reportedly observed a sharp increase in device-code phishing during 2026 and linked multiple EvilTokens backend IPs used for token replay to Railway-hosted infrastructure.
Okta's Threat Intelligence team said an EvilProxy campaign active since at least March 2025 is tracked as threat actor O-TA-041.
Sekoia's Threat Detection & Research team first identified the Sneaky 2FA phishing-as-a-service kit in December 2024.
Campaign activity associated with the Sneaky 2FA phishing kit was traced back to October 2024, indicating the platform was in use before its public identification.
In August 2023, Proofpoint and Menlo Security tracked an EvilProxy campaign targeting C-level executives and managers at more than 100 organizations globally.
EvilProxy has operated since May 2022 as a long-running commercial adversary-in-the-middle phishing service, marketed on dark-web forums.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.