A phishing package subverting Microsoft’s reputable authentication circulate lets attackers break into accounts with out stealing passwords or creating pretend login pages
15 Jun 2026
•
,
5 min. learn

A lot has been written about how the times of phishing emails laden with damaged grammar and crude design are numbered, largely due to AI. In the meantime, EvilTokens provides a considerably totally different instance of how far the phishing craft has moved.
EvilTokens is a phishing-as-a-service (PhaaS) package constructed to compromise Microsoft 365 accounts by abusing the OAuth 2.0 gadget authorization grant circulate. As assaults that use the package depend on gadget code phishing, they sidestep the necessity for convincing replicas of real login pages the place the victims would hand over their passwords. As an alternative, attackers get the sufferer to finish a reputable authentication course of – together with two-factor authentication (2FA) – on an actual Microsoft login web page.
The toolkit has been marketed by way of Telegram channels and noticed in lively assaults since a minimum of February 2026. As documented by Sekoia and others, the package seems to have been rapidly adopted by cybercriminals and deployed in quite a few account takeover and enterprise electronic mail compromise (BEC) assaults, together with for a marketing campaign focusing on greater than 340 organizations in a number of international locations in March 2026. Microsoft itself has additionally described an AI-enabled marketing campaign that used dynamic device-code technology and bespoke lures to extend the success fee of EvilTokens assaults.
The inside workings of EvilTokens
Right here’s a short overview of how assaults leveraging EvilTokens unfold:
- The assault itself is preceded by ‘reconnaissance’ the place the ne’er-do-wells first confirm that the goal account is lively. Microsoft has seen this reconnaissance run 10 to fifteen days forward of the particular phishing try.
- The sufferer receives an electronic mail or message that’s usually dressed up as an bill, shared doc, calendar invite, or SharePoint entry request. The lure includes a decoy web page impersonating a trusted model or service, together with easy wording comparable to “Confirm to view” or “Signature required.”
- When the sufferer clicks by way of, the web page requests a tool code from Microsoft. The code is legitimate just for quarter-hour, therefore time and timing are of the essence right here. The web page exhibits the sufferer the code alongside and factors them to Microsoft’s real microsoft.com/devicelogin login portal. The catch is that the code belongs to the attacker’s session, therefore the sufferer unknowingly authorizes the attacker’s gadget, not their very own.
- Seeing a legitimate sign-in, Microsoft points entry and refresh tokens to the session opened by the attacker. As soon as inside, the criminals can entry company electronic mail, recordsdata, Groups, SharePoint, OneDrive, and different Microsoft 365 sources and exfiltrate knowledge or put together BEC assaults, which is why finance, HR, logistics, and gross sales accounts draw a lot of the attackers’ curiosity.
What makes EvilTokens harmful
The OAuth gadget code circulate was designed for gadgets that could be awkward to signal into instantly, comparable to sensible TVs or printers. The gadget shows a brief code that the consumer enters on a Microsoft web page on one other gadget, usually a smartphone, and completes authentication there. Microsoft then points entry tokens to the gadget that requested entry.
That separation is helpful, however it leaves room for abuse. Attackers can generate the code and dupe the sufferer into getting into it – all whereas Microsoft solely sees a legitimate authentication circulate. The corporate does warn customers for the time being of sign-in by way of on-screen textual content telling them to not enter codes from sources that they don’t belief. Nevertheless, a convincing decoy is usually sufficient to get the sufferer to learn previous any warnings.
Talking of which, EvilTokens strips out lots of the pink flags that folks have been taught to note over time, together with misspelled domains and pretend login pages. The login web page is actual and, from the sufferer’s standpoint, your complete authentication course of can seem to work as anticipated.
The assault additionally ‘muddies the waters’ with regards to safeguards offered by 2FA. Whereas the second authentication layer has by no means been extra vital, it falls brief when the sufferer approves the unsuitable session. In these assaults, attackers don’t subvert 2FA by way of any technical wizardry – reasonably, they merely dupe the sufferer into finishing 2FA for them.
Tips on how to cut back the danger
Phishing safety suggestions clearly can’t cease at “examine the hyperlink,” not to mention “search for typos.” These habits nonetheless assist, after all, however they don’t maintain up towards trendy assaults, particularly those who abuse actual authentication flows.
Listed below are a number of suggestions for staying secure from EvilTokens:
- Consider any surprising request for an authentication code as suspect. No doc, bill, electronic mail, or one other platform ought to ask for a tool code with no clear purpose. If the request arrives out of nowhere, flag it to your employer’s IT or safety staff.
- Context issues greater than the web page. Earlier than approving any sign-in request, examine which app is asking for entry, which account is concerned, and whether or not you really began the motion. An actual Microsoft web page doesn’t routinely make a request secure.
- Organizations ought to limit gadget code circulate outright the place it’s not wanted. Microsoft recommends making use of Conditional Entry insurance policies to dam gadget code circulate wherever it isn’t mandatory and scope it to particular customers, gadgets, areas, or working programs.
- Look ahead to uncommon device-code authentication, unfamiliar gadgets, dangerous sign-ins, suspicious token use, and new inbox guidelines – any of those can level to hassle.
- Safety consciousness coaching must meet up with the most recent tips up attackers’ sleeves. Staff ought to perceive that trendy phishing doesn’t at all times contain typing a password right into a pretend web page. Typically the attacker might ask them to enter an actual code on an actual web page – however for the unsuitable gadget.
- Staff who obtain an surprising device-code request ought to notify their firm’s IT or safety groups, who might have to overview sign-in logs, revoke classes, invalidate refresh tokens, take away malicious inbox guidelines, and quickly disable the compromised account.
EvilTokens is a reminder that attackers don’t at all times want to interrupt the entrance door or steal the important thing to it. Typically they solely want to speak somebody into opening it.

