logo

EvilTokens Emerges as New Phishing-as-a-Service Platform for Microsoft Account Takeover

ID: 5cf64a4b-217a-5a24-b47f-8910b546ffd3

STIX ID: report--5cf64a4b-217a-5a24-b47f-8910b546ffd3

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-31

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

**EvilTokens is a Phishing-as-a-Service discovered in early 2026 that abuses Microsoft’s OAuth 2.0 device code flow to trick victims into authorizing attackers, allowing theft of access and long-lived refresh tokens (and in some cases conversion to PRT) for persistent Microsoft 365 account access; the platform—distributed via Telegram, offering templates, automation, and reconnaissance—has been widely adopted by criminals across multiple continents (over 1,000 domains tracked) and is used in BEC and AitM-style campaigns, with recommended mitigations including disabling unnecessary device code authentication, monitoring device_code grant sign-ins, YARA detection, and user training.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.