logo

EvilTokens: an AI-augmented Phishing-as-a-Service for automating BEC fraud – Part 2

ID: bb282cc9-b879-5fee-92cb-1edc01a18977

STIX ID: report--bb282cc9-b879-5fee-92cb-1edc01a18977

Feed Name: Sekoia.io Blog

Threat Score
80/100

Date Published: 2026-04-07

Date Updated: 2026-04-29

Author: Quentin Bourgue and Sekoia TDR

...
...

EvilTokens is a commercially-offered Phishing-as-a-Service that uses Microsoft device-code phishing to harvest access and refresh tokens, providing affiliates with a centralized admin panel, a built-in webmail interface, token weaponisation (including PRTs), and an AI-driven pipeline that analyzes stolen mailboxes and generates tailored BEC emails to scale fraud operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.