logo

New widespread EvilTokens kit: device code phishing as-a-service – Part 1

ID: 6c1cd69b-3028-5d4d-a527-ada31938ebc4

STIX ID: report--6c1cd69b-3028-5d4d-a527-ada31938ebc4

Feed Name: Sekoia.io Blog

Threat Score
78/100

Date Published: 2026-03-30

Date Updated: 2026-04-29

Author: Quentin Bourgue and Sekoia TDR

...
...

EvilTokens is a newly identified Phishing-as-a-Service (PhaaS) offering turnkey Microsoft device code phishing kits and a feature-rich backend that automates token harvesting, PRT conversion, browser SSO cookie generation, reconnaissance (Graph/Azure), and post-compromise persistence; the kit was rapidly adopted in early March 2026 with over 1,000 domains observed, multiple phishing templates and delivery vectors, and includes IoCs and a YARA rule for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.