216.73.216.36

New widespread EvilTokens kit: device code phishing as-a-service

· Published 31/03/2026 16:14 · Modified 31/03/2026 18:49

Export JSON

Essential information

Published
31/03/2026 16:14
Modified
31/03/2026 18:49
Tags
2026-03-31 account takeover business email compromise device code phishing eviltokens microsoft 365 oauth 2.0 phishing-as-a-service token harvesting
Related entities
10 techniques (mitre), 45 others

Description

is a new offering a turnkey Microsoft kit. It enables attackers to harvest access and refresh tokens, granting unauthorized access to victims' Microsoft accounts. The kit supports post-compromise operations, allowing data exfiltration from various Microsoft services. has been rapidly adopted by cybercriminals since March 2026, impacting organizations globally. The service provides advanced capabilities for , including token conversion to Primary Refresh Tokens and browser cookies for persistent access. Phishing campaigns using target employees in finance, HR, logistics, and sales, primarily for attacks.

External references