Skip to main content
Mallory

EvilTokens

Also known asEvilTokens

EvilTokens is a phishing-as-a-service (PhaaS) platform and turnkey Microsoft device code phishing kit that emerged in February 2026 and was documented by Sekoia in March 2026. It is sold via Telegram and has been linked to active Microsoft 365-focused campaigns affecting more than 340 organizations across five countries. The platform abuses Microsoft OAuth device authorization flow to obtain access and refresh tokens, enabling account takeover and practical MFA bypass because victims complete authentication on Microsoft’s legitimate device login page. Reported lure themes include voicemail notifications, DocuSign and Adobe document shares, construction bids, employee benefits, and other business-themed messages. Observed EvilTokens infrastructure and delivery tradecraft include Cloudflare Workers and workers.dev landing pages, Railway-hosted components, multi-hop redirect chains, open redirects on vulnerable domains, and abuse of trusted services such as Amazon S3, Vercel, AWS Amplify, Microsoft Dynamics 365 Customer Voice, and URL rewriting services from Cisco, Mimecast, Trend Micro, and others. Reports also describe anti-bot protections and CAPTCHA gating in associated campaigns. EvilTokens has been associated with both device code phishing and broader Microsoft 365 compromise activity used for business email compromise (BEC). Sekoia reported that EvilTokens provides affiliates with a centralized administration panel for harvested Microsoft tokens, built-in Outlook-like webmail access, token management, collaborative user and role management, and a custom Portal Browser (also called ET Browser) for simultaneous access to multiple compromised Microsoft 365 accounts. The backend was reported to request tokens for Outlook, Graph, Azure, Substrate, and SharePoint, perform Microsoft Graph reconnaissance, and exchange harvested tokens for a Primary Refresh Token for persistence. Sekoia also reported AI-augmented post-compromise tooling using Groq and OpenAI APIs to analyze stolen emails, identify financial exposure, and generate tailored BEC scenarios and draft emails. Known marketed products include B2B Sender, Office 365 Capture Link, SMTP Sender, and Portal Browser. No nation-state attribution is stated in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

11 of 15 tactics40 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1589×2
Gather Victim Identity Information
T1598×2
Phishing for Information
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1584
Compromise Infrastructure
T1584.006
Web Services
TA0001
Initial Access
3 techniques
T1078×9
Valid Accounts
T1078.004
Cloud Accounts
T1133
External Remote Services
T1566×15
Phishing
T1566.001×4
Spearphishing Attachment
T1566.002×5
Spearphishing Link
T1566.003
Spearphishing via Service
TA0003
Persistence
4 techniques
T1078×9
Valid Accounts
T1078.004
Cloud Accounts
T1098
Account Manipulation
T1133
External Remote Services
T1136×2
Create Account
TA0004
Privilege Escalation
2 techniques
T1078×9
Valid Accounts
T1078.004
Cloud Accounts
T1098
Account Manipulation
TA0005
Stealth
4 techniques
T1027
Obfuscated Files or Information
T1078×9
Valid Accounts
T1078.004
Cloud Accounts
T1497
Virtualization/Sandbox Evasion
T1564
Hide Artifacts
TA0006
Credential Access
3 techniques
T1528×8
Steal Application Access Token
T1557×3
Adversary-in-the-Middle
T1649×2
Steal or Forge Authentication Certificates
TA0007
Discovery
3 techniques
T1087×2
Account Discovery
T1497
Virtualization/Sandbox Evasion
T1526×2
Cloud Service Discovery
TA0008
Lateral Movement
2 techniques
T1534
Internal Spearphishing
T1550×2
Use Alternate Authentication Material
TA0009
Collection
5 techniques
T1114×3
Email Collection
T1114.003
Email Forwarding Rule
T1185×2
Browser Session Hijacking
T1213×2
Data from Information Repositories
T1530×2
Data from Cloud Storage
T1557×3
Adversary-in-the-Middle
TA0011
Command and Control
1 technique
T1104
Multi-Stage Channels
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping30

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.