logo

New widespread EvilTokens kit: device code phishing as-a-service

ID: 0d911d3e-9fad-58bf-b720-68b55e49f860

STIX ID: report--0d911d3e-9fad-58bf-b720-68b55e49f860

Feed Name: Sekoia.com

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-07-20

...
...

Sekoia TDR identified EvilTokens, a turnkey Phishing-as-a-Service that delivers Microsoft device code phishing pages and backend tooling to harvest access/refresh tokens, convert refresh tokens to Primary Refresh Tokens and SSO cookies, and perform reconnaissance and post-compromise actions; the kit has been rapidly adopted by affiliates, impacted organizations globally, and is trackable via specific domain patterns, API endpoints, HTTP headers, IoCs and a YARA rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.