Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 22 hostnames
EvilTokens is a phishing-as-a-service platform built to compromise Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 Device Authorization Grant flow.
Profile source: Mallory opens in a new tabEvilTokens
EvilTokens is a phishing-as-a-service platform built to compromise Microsoft 365 accounts by abusing Microsoft’s OAuth 2.0 Device Authorization Grant flow. Rather than harvesting passwords through counterfeit login pages, it presents victims with an attacker-generated device code and directs them to Microsoft’s legitimate device login experience, where the victim completes normal authentication and MFA on behalf of the attacker. This yields access and refresh tokens to the attacker and can enable persistent unauthorized access without password theft.
The platform emerged in early 2026 and was rapidly adopted by financially motivated phishing and business email compromise operators. It has been associated with campaigns targeting organizations worldwide, with repeated focus on finance, HR, logistics, sales, accounts payable, and other business functions that are valuable for fraud and mailbox intelligence. Observed lure themes include invoices, shared documents, document-signing workflows, voicemail notifications, SharePoint or OneDrive access requests, calendar invites, password-expiry notices, and quarantine notifications. Delivery has been observed through phishing emails, malicious document attachments, intermediary PDFs, Cloudflare Workers-hosted phishing pages, and calendar-invite workflows.
EvilTokens supports more than initial token capture. Reported capabilities include token refresh, conversion or escalation of stolen authentication material into longer-lived session artifacts such as Primary Refresh Tokens, browser single sign-on cookie generation, Outlook Web Access session generation, Microsoft Graph and Azure reconnaissance, and mailbox access that can facilitate business email compromise. Associated tooling and related panels linked to the ecosystem have exposed features for inbox monitoring, keyword-based surveillance, inbox-rule manipulation, email sending as the victim, and access to SharePoint and OneDrive data. The ecosystem has also been tied to AI-assisted lure generation and operational automation, lowering the barrier to entry for affiliates.
The platform has been sold through Telegram-based channels on a subscription model and has been linked to large-scale phishing operations compromising Microsoft accounts across multiple sectors and regions. EvilTokens is notable because it removes many traditional phishing indicators: victims authenticate against legitimate Microsoft infrastructure, MFA may succeed normally, and password resets alone may not fully remediate compromise once refresh-token or PRT-style persistence has been established.
C2 tracking
Derp observations, rolling seven-day window
Samples
341646b8422b229cb315cc64bbbc2fe00da4d41a0bf73fc9d115933ce43b01ea 74fce6147318970006cd2cee2c99f700f28b3cd27cfd4ae8074e1f9c321568fb 9740eebfb37ced4358ee204823c738ae81ec5de9821e24f82e3c87d34b4f1db8 582e2e46483a9be1ee231d527bd7bcd71f5bc5e86da97e805f8c5e0d1614fc84 6fd65bb85cd5862d5ad8495903b9080bdeee0da140a7fe3b658db94d20401257 987aba1bc2fa4c97f6f4266d0341b6230cf1857cdc1c682bc77047241dd45d82 c21b04caa96bb6157ed4674d9a0aeb4d3ab3758fc64ed125e88897cdc61cc27e 0947f11a406f41718eb35ab4c60ca57abb6a5b69b82415540ded81bace07be1d 5f388c9d57607972a44976ceef8a4577d02812aef1e199fcbc3f377d91519c1a 8527a94c407eed3763c407dfbab625829c1ddc536a2858315acb563e063eda41 Reported operators
A “Review and Sign” button then redirected the victim to an EvilTokens device code harvesting page disguised as an Adobe Acrobat document-sharing authentication screen.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
MITRE ATT&CK
Reporting
Researchers reported that the EvilTokens phishing-as-a-service platform is being used to steal Microsoft 365 access tokens through OAuth device code phishing, with one campaign abusing free Notion accounts and malicious PDFs to lure victims. In the activity tracked as Doubloon Dredger, attackers sent legitimate-looking Notion document-sharing notifications from compromised accounts impersonating senior executives, then redirected targets to phishing pages disguised as Adobe Acrobat authentication prompts. Victims were instructed to enter a verification code on Microsoft’s legitimate sign-in or device code page, allowing Microsoft to issue authorization tokens directly to the attackers without requiring password theft. The operation has targeted organizations in manufacturing, telecommunications, retail, healthcare, and logistics, and researchers said EvilTokens has been active since at least February 2026 and is marketed largely through Telegram. Flare said the platform goes beyond session theft by analyzing compromised mailboxes, using AI to summarize content and identify likely fraud opportunities, and helping operators craft tailored business email compromise messages based on real payment workflows and relationships. Reported activity included a 16-day wave affecting 344 organizations across five countries, while separate research found more than 1,000 infrastructure-related search results and 66 email attachments leading to EvilTokens pages; defenders were urged to restrict or disable device-code authentication where possible and monitor for anomalous token grants, inbox rule creation, mailbox searches, token reuse, and suspicious outbound email.
A widespread phishing campaign is compromising Microsoft 365 accounts with adversary-in-the-middle login pages that capture session material even when MFA is enabled, then using those identities to target payroll, HR, finance, and administrative staff across healthcare, education, manufacturing, government, and professional services in the United States, Canada, and Europe. Arctic Wolf said the activity aligns technically and behaviorally with Microsoft-tracked Storm-2755 (also known as Payroll Pirates), with attackers maintaining access through rotating residential proxies and automated session activity roughly every eight hours while quietly collecting mailbox data tied to financial workflows. Reporting also shows the intrusions can progress without additional device compromise, shifting instead into identity-plane lateral movement inside Entra ID and Microsoft 365. After an initial phish, attackers can use stolen session tokens to enumerate the tenant through Microsoft Graph, register a malicious Entra ID application, create a service principal, grant permissions such as Mail.Read and Mail.Send, and access other users’ mailboxes, including executives, before sending fraudulent messages through Graph API that pass SPF and DKIM checks. Defenders were urged to correlate cloud identity, Graph, sign-in, and email telemetry for signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, repeated SessionID reuse across changing IPs and geographies, suspicious app registrations, credential additions to service principals, and unusual application access to user mailboxes.
Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.