Last seven days
- First activity
- Aug 4, 2026
- Last activity
- Aug 8, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 20 hostnames
EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by abusing the OAuth 2.0 Device Authorization Grant flow.
Profile source: Mallory opens in a new tabEvilTokens
EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by abusing the OAuth 2.0 Device Authorization Grant flow. Rather than harvesting passwords through counterfeit login pages, it tricks victims into entering an attacker-generated Microsoft device code on Microsoft’s legitimate device login page and completing normal authentication, including multifactor authentication. This causes Microsoft to issue access and refresh tokens to the attacker’s session, enabling account takeover without direct credential theft.
The platform is associated with large-scale phishing and business email compromise activity observed since at least early 2026. Campaigns have targeted organizations globally and have frequently focused on finance, human resources, logistics, sales, and accounts-payable personnel. Lures commonly impersonate business workflows such as invoices, shared documents, voicemail notifications, calendar invites, SharePoint access requests, document-signature requests, and password-expiry or quarantine notices. Delivery has been observed through phishing emails and malicious attachments or linked documents, including formats such as PDF, HTML, DOCX, XLSX, and SVG, as well as calendar-invite themed campaigns.
EvilTokens provides turnkey phishing pages that display a verification code, instructions, and a redirect into Microsoft’s legitimate device login flow. Reported backend functionality includes automated device-code generation and polling, token capture, token refresh, conversion of stolen authentication material into longer-lived access such as Primary Refresh Tokens, browser single sign-on cookie generation, Outlook Web Access session generation, and reconnaissance against Microsoft 365, Entra ID, Microsoft Graph, and Azure resources. The platform has also been linked to post-compromise operations including mailbox access, SharePoint and OneDrive access, data theft, persistence, and business email compromise workflows. Reporting also indicates Telegram-based operator notifications and a broader affiliate-style ecosystem, with technically related panels such as ARToken showing shared infrastructure, API patterns, and operational lineage.
EvilTokens is notable for reducing traditional phishing indicators because victims authenticate on genuine Microsoft infrastructure. Its emergence marked the industrialization of device-code phishing at scale and contributed to a broader rise in token-theft-driven Microsoft 365 intrusions that can persist beyond password resets when attackers successfully weaponize refresh-token or device-registration workflows.
Reported operators
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.
MITRE ATT&CK
Reporting
A widespread phishing campaign is compromising Microsoft 365 accounts with adversary-in-the-middle login pages that capture session material even when MFA is enabled, then using those identities to target payroll, HR, finance, and administrative staff across healthcare, education, manufacturing, government, and professional services in the United States, Canada, and Europe. Arctic Wolf said the activity aligns technically and behaviorally with Microsoft-tracked Storm-2755 (also known as Payroll Pirates), with attackers maintaining access through rotating residential proxies and automated session activity roughly every eight hours while quietly collecting mailbox data tied to financial workflows. Reporting also shows the intrusions can progress without additional device compromise, shifting instead into identity-plane lateral movement inside Entra ID and Microsoft 365. After an initial phish, attackers can use stolen session tokens to enumerate the tenant through Microsoft Graph, register a malicious Entra ID application, create a service principal, grant permissions such as Mail.Read and Mail.Send, and access other users’ mailboxes, including executives, before sending fraudulent messages through Graph API that pass SPF and DKIM checks. Defenders were urged to correlate cloud identity, Graph, sign-in, and email telemetry for signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, repeated SessionID reuse across changing IPs and geographies, suspicious app registrations, credential additions to service principals, and unusual application access to user mailboxes.
Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.