EvilTokens is a phishing-as-a-service platform built to compromise Microsoft 365 accounts by abusing the OAuth 2.0 Device Authorization Grant flow. Rather than harvesting passwords through counterfeit login pages, it tricks victims into entering an attacker-generated device code on Microsoft’s legitimate device login page, causing Microsoft to issue access and refresh tokens to the attacker-controlled session. Because the victim authenticates through genuine Microsoft infrastructure, the technique can defeat the protections normally expected from multi-factor authentication and leaves fewer traditional phishing indicators than credential-harvesting kits.
The platform has been advertised through Telegram and was observed in active use from at least early 2026. It provides turnkey phishing templates themed as invoices, shared documents, calendar invites, SharePoint access requests, voicemail notices, password expiry warnings, and trusted business-service workflows. Delivery has been observed through phishing emails and malicious attachments or linked documents in formats such as PDF, HTML, DOCX, XLSX, and SVG. Campaigns have commonly targeted finance, human resources, logistics, sales, and accounts-payable personnel to support account takeover and business email compromise operations.
EvilTokens includes substantial post-compromise functionality beyond initial token capture. Reported capabilities include token polling and refresh, conversion of stolen authentication material into Primary Refresh Tokens for longer-lived persistence, browser single sign-on cookie generation, Outlook Web Access session generation, Microsoft Graph and Azure reconnaissance, and access to victim Microsoft 365 resources including Outlook, Teams, SharePoint, and OneDrive. The platform has also been associated with business email compromise workflows such as mailbox monitoring, inbox-rule abuse, and follow-on fraud activity.
The ecosystem appears to support affiliate-style operations and has been linked to related panels such as ARToken, which shares infrastructure, API patterns, deployment models, and token-management workflows with EvilTokens. Researchers have described EvilTokens as one of the first phishing-as-a-service offerings to industrialize Microsoft device-code phishing at scale, with broad global targeting and infrastructure spanning a large number of phishing pages and domains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The victim sees real Microsoft authentication surfaces, but the code authorizes an attacker-controlled session.
Forg365 includes a device-auth phishing branch that presents a Microsoft-styled verification code page and pushes the victim into a legitimate Microsoft Authentication Broker sign-in flow. The victim sees real Microsoft authentication surfaces, but the code authorizes an attacker-controlled session.
the “from” header presents the contractor’s real domain. The reply-to, however, redirects replies to an unrelated domain. Even the visible anchor text in the body of the email reads as the vendor's genuine SharePoint tenant.
The victim sees real Microsoft authentication surfaces, but the code authorizes an attacker-controlled session.
Automatisation des opérations de Business Email Compromise (BEC)
a built-in business email compromise (BEC) tool with full Microsoft Outlook inbox read access
Accès complet aux boîtes Outlook ... Surveillance simultanée de plusieurs boîtes compromises par mots-clés
146 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing kit used in device code phishing campaigns, reached through multiple redirect and infrastructure hops before presenting the phishing flow.
Commercial phishing platform associated with Microsoft 365 device code phishing and BEC enablement. The content describes it as a commercial PhaaS offering with similar OAuth device authorization, PRT-related endpoints, Cloudflare Workers deployment, and AI/LLM-assisted workflow for scoring mailbox value and automating BEC campaigns.
Related PhaaS platform sharing infrastructure, API contracts, PRT lifecycle endpoints, Cloudflare Workers deployment patterns, and multi-tenant operational model with ARToken.
A phishing-as-a-service platform associated with device code phishing operations; ARToken appears to be a rebranded or closely related offshoot sharing infrastructure and backend behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.