Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceidentity-authentication-vulnerabilitycybercrime-service-ecosystemcredential-access-method

EvilTokens Turns Microsoft Device Code Phishing Into a Scalable Account Takeover Service

Updated 3mo agoFirst seen Mar 31, 20268 sources

Researchers identified EvilTokens as a new phishing-as-a-service platform built to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate OAuth 2.0 device code authentication flow. Sold and operated through Telegram bots, the service gives affiliates phishing templates, email harvesting and reconnaissance features, automated Microsoft API interactions, webmail access, and mailbox triage capabilities. Victims are lured into entering attacker-supplied device codes on Microsoft’s real login page, allowing attackers to capture access and refresh tokens—and in some cases a Primary Refresh Token—without stealing passwords or directly defeating MFA.

Security teams linked a sharp rise in device code phishing to EvilTokens, describing it as the first known turnkey PhaaS offering dedicated Microsoft device code phishing pages and warning that it lowers the barrier for low-skill operators. More than 1,000 phishing domains were observed by late March, with campaigns affecting organizations worldwide and notable activity in the United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates; finance, HR, and transportation/logistics staff were highlighted as frequent targets. Researchers from Sekoia and Mnemonic urged defenders to disable or restrict unnecessary device code flows in Microsoft Entra ID, monitor device code grant sign-ins for anomalies, train users on device authentication abuse, and revoke refresh tokens when compromise is suspected.

Share:
EvilTokens Turns Microsoft Device Code Phishing Into a Scalable Account Takeover Service
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 4, 20263mo ago

Push Security reports 37.5x surge in device code phishing and 11 active kits

On 2026-04-04, Push Security reported that device code phishing attacks abusing OAuth 2.0 Device Authorization Grant had increased 37.5 times in 2026. The researchers said EvilTokens was a major driver but identified at least 11 phishing kits using SaaS-themed lures, anti-bot protections, and cloud-hosted infrastructure, indicating broader criminal adoption of the technique.

Device code phishing attacks surge 37x as new kits spread online
Apr 1, 20263mo ago

EvilTokens author plans Gmail and Okta phishing support

By 2026-04-01, Sekoia reported that EvilTokens was under active development and that its author planned to add phishing pages targeting Gmail and Okta. This marked an expansion of the platform beyond Microsoft 365-focused device code phishing.

New EvilTokens service fuels Microsoft device code phishing attacks
Mar 31, 20263mo ago

Public reporting warns of EvilTokens-driven rise in device code phishing

On 2026-03-31, public reports disclosed EvilTokens as a new phishing-as-a-service platform and warned of a notable increase in Microsoft 365 device code phishing tied to the toolkit. The reporting also shared mitigations such as restricting device code flows, monitoring sign-ins, and revoking refresh tokens after suspected compromise.

Mar 23, 20263mo ago

More than 1,000 EvilTokens phishing domains observed

By 2026-03-23, researchers had observed more than 1,000 phishing domains associated with EvilTokens. Reported targeting included organizations in the United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates.

Mar 1, 20264mo ago

Researchers identify and analyze EvilTokens activity

In March 2026, Sekoia's Threat Detection and Research team identified EvilTokens and, together with Mnemonic, assessed that it was helping scale device code phishing into a broader threat. Sekoia also assessed with high confidence that the platform's backend code was likely AI-generated.

EvilTokens campaigns spread globally via Telegram-operated infrastructure

By March 2026, EvilTokens was being operated through Telegram bots and used in campaigns targeting organizations worldwide, with tooling for phishing templates, reconnaissance, webmail access, and automation. The activity was linked to increased device code phishing against Microsoft 365 users, particularly affecting sectors such as finance, HR, and transportation/logistics.

Jan 1, 20266mo ago

EvilTokens PhaaS emerges targeting Microsoft 365 device code flow

In early 2026, EvilTokens emerged as a phishing-as-a-service platform built to hijack Microsoft 365 accounts by abusing Microsoft's legitimate OAuth 2.0 device code authentication flow. Researchers described it as the first known turnkey PhaaS offering dedicated Microsoft device code phishing pages.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Malware
1 linked
Affected products
9 linked
DocusignMicrosoft OfficeOnedriveSharepointEntra IdMicrosoft Entra IdGmailMicrosoft AccountGmail
Organizations
19 linked
Microsoft CorporationSekoiaDocuSignAdobeOktaTencentAmazon Web ServicesDigitaloceanCloudflarePush SecurityCitrix SystemsGitHubDolce & GabbanaBleepingComputerTelegramGoogleLinkedinXMnemonic
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.