Skip to content

EvilTokens

EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by abusing the OAuth 2.0 Device Authorization Grant flow.

Profile source: Mallory opens in a new tab

EvilTokens

Family profile

EvilTokens is a phishing-as-a-service platform focused on compromising Microsoft 365 accounts by abusing the OAuth 2.0 Device Authorization Grant flow. Rather than harvesting passwords through counterfeit login pages, it tricks victims into entering an attacker-generated Microsoft device code on Microsoft’s legitimate device login page and completing normal authentication, including multifactor authentication. This causes Microsoft to issue access and refresh tokens to the attacker’s session, enabling account takeover without direct credential theft.

The platform is associated with large-scale phishing and business email compromise activity observed since at least early 2026. Campaigns have targeted organizations globally and have frequently focused on finance, human resources, logistics, sales, and accounts-payable personnel. Lures commonly impersonate business workflows such as invoices, shared documents, voicemail notifications, calendar invites, SharePoint access requests, document-signature requests, and password-expiry or quarantine notices. Delivery has been observed through phishing emails and malicious attachments or linked documents, including formats such as PDF, HTML, DOCX, XLSX, and SVG, as well as calendar-invite themed campaigns.

EvilTokens provides turnkey phishing pages that display a verification code, instructions, and a redirect into Microsoft’s legitimate device login flow. Reported backend functionality includes automated device-code generation and polling, token capture, token refresh, conversion of stolen authentication material into longer-lived access such as Primary Refresh Tokens, browser single sign-on cookie generation, Outlook Web Access session generation, and reconnaissance against Microsoft 365, Entra ID, Microsoft Graph, and Azure resources. The platform has also been linked to post-compromise operations including mailbox access, SharePoint and OneDrive access, data theft, persistence, and business email compromise workflows. Reporting also indicates Telegram-based operator notifications and a broader affiliate-style ecosystem, with technically related panels such as ARToken showing shared infrastructure, API patterns, and operational lineage.

EvilTokens is notable for reducing traditional phishing indicators because victims authenticate on genuine Microsoft infrastructure. Its emergence marked the industrialization of device-code phishing at scale and contributed to a broader rise in token-theft-driven Microsoft 365 intrusions that can persist beyond password resets when attackers successfully weaponize refresh-token or device-registration workflows.

Capabilities

  • Exfiltration
  • Extortion
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking
  • Spoofing

Observed infrastructure

Last seven days

First activity
Aug 4, 2026
Last activity
Aug 8, 2026
Feed role
Distribution
Host form
0 IP / 20 hostnames

Leading locations

  • US18
  • DE1

Leading providers

  • Cloudflare, Inc.13
  • Datacamp Limited5
  • Hetzner Online GmbH1

Infrastructure traits

  • Hosting 19
  • Anycast 13
  • Vpn 5

Reported operators

Threat actors

2 named in public reporting
Storm-2372

BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.

TA4903

BGD e-GOV CIRT is issuing this advisory to raise awareness of EvilTokens, a Phishing-as-a-Service (PhaaS) kit that abuses the legitimate Microsoft OAuth 2.0 Device Authorization Grant (device code) flow to steal persistent Microsoft 365 access and refresh tokens without requiring password theft or triggering suspicious MFA prompts.

MITRE ATT&CK

EvilTokens in ATT&CK

42 distinct techniques

Reporting

Research mentioning EvilTokens

Aug 6
Malware News

Payroll Pirates: Strange New Tides in Business Email Compromise - Malware News - Malware Analysis, News and Indicators

A widespread phishing campaign is compromising Microsoft 365 accounts with adversary-in-the-middle login pages that capture session material even when MFA is enabled, then using those identities to target payroll, HR, finance, and administrative staff across healthcare, education, manufacturing, government, and professional services in the United States, Canada, and Europe. Arctic Wolf said the activity aligns technically and behaviorally with Microsoft-tracked Storm-2755 (also known as Payroll Pirates), with attackers maintaining access through rotating residential proxies and automated session activity roughly every eight hours while quietly collecting mailbox data tied to financial workflows. Reporting also shows the intrusions can progress without additional device compromise, shifting instead into identity-plane lateral movement inside Entra ID and Microsoft 365. After an initial phish, attackers can use stolen session tokens to enumerate the tenant through Microsoft Graph, register a malicious Entra ID application, create a service principal, grant permissions such as Mail.Read and Mail.Send, and access other users’ mailboxes, including executives, before sending fraudulent messages through Graph API that pass SPF and DKIM checks. Defenders were urged to correlate cloud identity, Graph, sign-in, and email telemetry for signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, repeated SessionID reuse across changing IPs and geographies, suspicious app registrations, credential additions to service principals, and unusual application access to user mailboxes.

Aug 6
Arctic Wolf

Payroll Pirates: Strange New Tides in Business Email Compromise - Arctic Wolf

Aug 4
Detect

Attackers Don’t Need Your Devices Anymore They Just Need Your Identity. | by Rohitashokgowd | Aug, 2026 | Detect FYI

Jul 23
Knowbe4

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Active phishing campaigns are using the Jalisco and OmegaLord kits to compromise Microsoft 365 accounts with techniques designed to bypass or weaken multi-factor authentication. According to ReliaQuest, Jalisco abuses the OAuth 2.0 device authorization flow by generating fresh Microsoft device codes in real time and tricking victims into authorizing attacker-controlled devices, allowing attackers to obtain OAuth tokens without directly stealing passwords. OmegaLord uses a fake PDF reader login page to harvest credentials and victims’ phone numbers, which may help attackers intercept or manipulate MFA challenges. After gaining access, attackers have been observed moving quickly through SharePoint and other SaaS platforms to locate and exfiltrate sensitive data, sometimes within minutes, and may follow with extortion threats. ReliaQuest also reported that threat actors register multiple devices to compromised Microsoft Entra ID accounts to preserve access and refresh tokens even after password resets, reflecting a broader surge in phishing-as-a-service activity tied to platforms including EvilTokens, Kali365, Tycoon2FA, Venom, and Darcula. Defenders are being urged to reduce Entra ID device-registration limits, disable or restrict device code authentication through Conditional Access or Okta where not needed, and audit unnecessary app registrations.

Jul 18
Infosec Writeups

Medium

Jul 15
Techrepublic Com Security

Jalisco, OmegaLord Phishing Kits Target Microsoft 365 Accounts

Jul 14
ReliaQuest

Threat Spotlight: The Jalisco Toolkit and AI-Powered Phishing Surge

Jul 14
Bleeping Computer

New phishing kits target Microsoft 365 accounts, evade MFA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.