EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, payments, and conversations most likely to produce fraud.
Unlike a conventional credential-stealing kit, the operation uses a real Microsoft sign-in process. A lure sends the target to a controlled page, where a device code is created and the user is directed to Microsoft’s authentic login site to approve it.
That same OAuth device code phishing pattern leaves victims at a genuine destination, not a counterfeit page.
Flare said in a report shared with Cyber Security News (CSN) that EvilTokens was first documented in February 2026 and is sold mainly through Telegram.
Its offer couples session capture with post-compromise analysis, making the service useful even to affiliates with limited knowledge of financial fraud.
The reported scale is notable, but estimates should not be merged. A 16-day wave affected 344 organizations across five countries, while separate research found more than 1,000 infrastructure-related search results and 66 email attachments leading to EvilTokens pages. Together, the findings show a service moving quickly from advertising into use.
EvilTokens Doesn’t Just Steal Microsoft Sessions
The decisive feature is what happens after token theft. EvilTokens searches mailboxes for invoices, payment requests, pending transactions, and past exchanges.
It then identifies suppliers, decision-makers, and people who approve payments, while mapping the normal language and approval steps used by the organization.
That information gives attackers a shortcut to a believable follow-up scam. The platform’s AI functions summarize the email data and create messages shaped around real business relationships.
Instead of guessing who should receive a fake invoice or urgent payment request, an affiliate can target a known, trusted contact.
This is why the Microsoft 365 phishing panel reports matter. Related panels show that device-code abuse is becoming a repeatable service rather than a one-off technique.
EvilTokens applies the model to the difficult stage: turning a valid session into an understanding of a company’s money flow and the people inside it.
The platform can also make the fraud faster and more personal. By using details from authentic conversations, criminals can imitate a vendor or colleague without starting from a generic template.
That lowers the experience needed to conduct business email compromise and increases the pressure on finance teams.
The result is an attack chain that combines access, research, and impersonation in one subscription. It also reframes the risk of a stolen token: the intruder may not merely read email, but use the mailbox to select the next victim and prepare a tailored request.
Device-Code Attacks Demand Tighter Controls
EvilTokens does not need to capture a password or defeat MFA in the usual sense. The victim completes both on a legitimate Microsoft page, but unknowingly approves the attacker’s waiting session. Microsoft then issues tokens to the session initiated by the criminal.
The timing is calculated. Microsoft device codes last 15 minutes, so the service generates a fresh code only when a target opens the phishing page.
This ongoing token theft campaign approach makes the approval look routine while ensuring the attacker still has time to collect the issued tokens.
.webp)
Organizations should restrict device-code authentication to approved needs, or disable it where it is not required.
Security teams should alert on unexpected device-code grants, unfamiliar devices, unusual locations, new token issuance, and suspicious consent activity. Shorter token lifetimes and prompt session revocation can reduce the value of a successful approval.
Users also need a simple rule: a real login page does not prove that a request is safe. They should treat unexpected codes, approval prompts, and verification requests as suspicious and report them.
Coverage of an earlier EvilTokens campaign shows why familiar Microsoft branding can make these lures persuasive.
Defenders should also watch what follows a successful sign-in: large mailbox searches, new inbox rules, token reuse, access to cloud data, and messages sent in a user’s name.
The OAuth device code phishing trend makes clear that detection cannot stop at the original email. It must continue through the account activity that follows.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

