logo

New EvilTokens service fuels Microsoft device code phishing attacks

ID: ae02e319-fb3c-5182-835d-0716d72550e0

STIX ID: report--ae02e319-fb3c-5182-835d-0716d72550e0

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-04-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed EvilTokens, a phishing-as-a-service kit sold on Telegram that leverages OAuth 2.0 device authorization (device code phishing) to obtain short-lived access and refresh tokens for Microsoft accounts. The service provides phishing templates (QR/hyperlink lures) tailored to finance/HR/logistics roles, automation features for business email compromise, and has been used in global campaigns; Sekoia published IoCs, YARA rules, and technical analysis to help defenders block these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.