Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecybercrime-service-ecosystemidentity-authentication-vulnerabilityai-enabled-threat-activity

EvilTokens Scales AI-Driven Microsoft 365 Token Phishing via Device Code OAuth

Updated 9h agoFirst seen Jun 24, 20262 sources

The phishing-as-a-service platform EvilTokens sharply expanded attacks against Microsoft 365 accounts by abusing Microsoft’s legitimate device code OAuth flow to steal access tokens after victims completed real Microsoft logins and multi-factor authentication. Huntress reported a 1,380% increase in device code phishing activity between late 2025 and early 2026, with campaigns affecting hundreds of organizations. The operation used AI-generated personalized phishing lures and automated post-compromise analysis to support follow-on business email compromise, while relying on legitimate cloud services including Railway, BL Networks/BitLaunch, and Cloudflare Workers to blend in with normal traffic.

EvilTokens was marketed openly on Telegram as a subscription service priced from $600 to $1,500, lowering the barrier for less sophisticated criminals to launch token-theft campaigns that can bypass MFA protections. Huntress said 57.5% of observed attacks were tied to Railway or BL Networks infrastructure, and that blocking Railway IP addresses through Conditional Access prevented more than 600 incidents before attackers shifted hosting. Defenders were urged to restrict or block device code authentication where possible, review sign-in logs for suspicious Railway-originated authentications, revoke stolen tokens, audit Microsoft Graph API activity, and update user awareness training because genuine Microsoft login pages can still be part of a phishing attack.

Share:
EvilTokens Scales AI-Driven Microsoft 365 Token Phishing via Device Code OAuth
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 24, 20261d ago

Defenders block Railway IPs to stop over 600 incidents

Huntress said that blocking Railway IP addresses through Conditional Access prevented more than 600 incidents before attackers shifted to other infrastructure. The report also linked 57.5% of observed attacks to Railway or BL Networks/BitLaunch.

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete - IT Security Guru

Huntress observes surge in device code phishing attacks

Huntress reported a 1,380% increase in device code phishing attacks between July–December 2025 and January–April 2026. The activity affected hundreds of organizations and was tied to EvilTokens' use of Microsoft's legitimate device code OAuth flow to steal Microsoft 365 access tokens after real logins and MFA.

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete - IT Security Guru

EvilTokens markets phishing service on Telegram

The EvilTokens phishing-as-a-service platform was advertised on Telegram with subscription pricing starting at $600, lowering the barrier to entry for token-theft and phishing operations.

AI-Powered Phishing Attacks Surge 1,380% as Criminal Platforms Render MFA Obsolete - IT Security Guru
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Microsoft 365
Organizations
10 linked
HuntressTech RadarTrend MicroCisco SystemsMimecastCloudflareMicrosoft CorporationBitLaunchBl NetworksRailway
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.