New widespread EvilTokens kit: device code phishing as-a-service – Part 1
ID: 6c1cd69b-3028-5d4d-a527-ada31938ebc4
STIX ID: report--6c1cd69b-3028-5d4d-a527-ada31938ebc4
Feed Name: Sekoia.io Blog
Date Published: 2026-03-30
Date Updated: 2026-04-29
Author: Quentin Bourgue and Sekoia TDR
EvilTokens is a newly identified Phishing-as-a-Service (PhaaS) offering turnkey Microsoft device code phishing kits and a feature-rich backend that automates token harvesting, PRT conversion, browser SSO cookie generation, reconnaissance (Graph/Azure), and post-compromise persistence; the kit was rapidly adopted in early March 2026 with over 1,000 domains observed, multiple phishing templates and delivery vectors, and includes IoCs and a YARA rule for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
