New widespread EvilTokens kit: device code phishing as-a-service
Essential information
- Published
- 31/03/2026 16:14
- Modified
- 31/03/2026 18:49
- Tags
- 2026-03-31 account takeover business email compromise device code phishing eviltokens microsoft 365 oauth 2.0 phishing-as-a-service token harvesting
- Related entities
- 10 techniques (mitre), 45 others
Description
EvilTokens is a new Phishing-as-a-Service offering a turnkey Microsoft device code phishing kit. It enables attackers to harvest access and refresh tokens, granting unauthorized access to victims' Microsoft accounts. The kit supports post-compromise operations, allowing data exfiltration from various Microsoft services. EvilTokens has been rapidly adopted by cybercriminals since March 2026, impacting organizations globally. The service provides advanced capabilities for account takeover, including token conversion to Primary Refresh Tokens and browser cookies for persistent access. Phishing campaigns using EvilTokens target employees in finance, HR, logistics, and sales, primarily for Business Email Compromise attacks.