logo

Arctic Wolf Tracking Threat Actors Abusing Railway PaaS for Microsoft 365 Token Compromise

ID: c4cff57c-ee60-599a-9489-33fee76d72f2

STIX ID: report--c4cff57c-ee60-599a-9489-33fee76d72f2

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2026-03-27

Date Updated: 2026-06-11

...
...

Arctic Wolf warns of an active EvilTokens phishing campaign targeting Microsoft 365 that leverages the OAuth device code flow and hosts attack components on Railway PaaS to steal access and refresh tokens, bypass multi‑factor authentication, and maintain persistent access; hundreds of organizations have been impacted. Recommended mitigations include blocking Device Code Flow with Conditional Access where not required, restricting it to specific networks/devices/users when needed, enabling sign‑in risk policies, and implementing phishing-focused security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.