logo

EvilTokens ramps up device code phishing targeting Microsoft 365 users

ID: d488cf4e-05d2-58e3-9037-fd115973ac62

STIX ID: report--d488cf4e-05d2-58e3-9037-fd115973ac62

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Security researchers report a notable increase in device-code phishing against Microsoft 365 driven by EvilTokens, a Telegram-distributed phishing-as-a-service that automates lure creation, Microsoft API interactions, and harvesting of access/refresh tokens (and potentially PRTs) to bypass MFA and maintain persistent account access; the kit includes ready-made templates targeting finance, HR and logistics and provides post-compromise triage features, and defenders are advised to train users, restrict device code authentication via Conditional Access, monitor anomalous sign-ins, and revoke suspected refresh tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.