logo

Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure

ID: 7c0c6d9a-279a-53a4-acbb-23af613376b7

STIX ID: report--7c0c6d9a-279a-53a4-acbb-23af613376b7

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-03-23

Date Updated: 2026-04-28

...
...

Huntress documents an active, high-volume device-code phishing campaign that weaponizes Railway.com infrastructure and a separate phishing delivery ecosystem (including workers.dev, compromised sites, and email-security URL rewriters) to harvest Microsoft 365 OAuth tokens across 344 organizations; the report includes IOCs (Railway IP ranges and CIDRs, Cloudflare workers patterns, UA fingerprints), attribution to the EvilTokens phishing-as-a-service platform, detailed detection queries, and remediation guidance such as blocking Railway CIDRs, revoking refresh tokens, and tightening Conditional Access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.