logo

EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords

ID: de59ba1d-661e-5c63-867b-6faa77afde9a

STIX ID: report--de59ba1d-661e-5c63-867b-6faa77afde9a

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Mayura Kathir

...
...

EvilTokens is a phishing-as-a-service that abuses Microsoft’s Device Authorization Grant to trick victims into approving legitimate sign-ins (including MFA) that issue attacker-controlled Microsoft 365 tokens; the service, advertised since Feb 2026, combines a commercial panel/subscription model with AI-augmented post-compromise tooling to support account reconnaissance, SharePoint access, and business email compromise, and has been linked to a campaign affecting hundreds of organizations across multiple countries—defenders are advised to restrict device-code authentication, apply Conditional Access, and alert on anomalous device-code grants and mailbox/SharePoint activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.