logo

EvilTokens Launches New Phishing Service Targeting Microsoft Accounts

ID: af14b373-c3ec-564e-936e-caf8c2d6a990

STIX ID: report--af14b373-c3ec-564e-936e-caf8c2d6a990

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Sekoia describes EvilTokens, a commercial Phishing-as-a-Service that weaponises Microsoft OAuth device code authentication to steal access and long‑lived refresh tokens, enabling immediate and persistent access to Microsoft 365 accounts; the platform provides turnkey phishing templates, automated token conversion and reconnaissance tooling, is delivered via Telegram bots, and has been observed in broad BEC-style campaigns across multiple regions with over 1,000 hosting domains and identifiable IOCs (API paths, X-Antibot-Token header, and an AES‑GCM decryption fingerprint).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.