The CyberSignal
  • Latest
  • Trending
  • Cyber Attacks
  • Data Breaches
  • Threat Intelligence
  • Critical Infrastructure
  • Policy & Government
  • Cybersecurity 101
  • Vulnerabilities
  • About Us
  • Weekly Briefing
Trending

Microsoft 365 Users Targeted by AI-Augmented EvilTokens Phishing Service

Nicholas Robert

Nicholas Robert

09 Apr 2026 — 3 min read
Share
A white Windows logo is struck by a yellow lightning bolt, shattering it into pixels and data tokens that drift away. Paper texture.

A novel Phishing-as-a-Service platform is leveraging Microsoft's device code flow to bypass multi-factor authentication and automate business email compromise at scale.

REDMOND — Security researchers have identified a surge in high-velocity phishing campaigns powered by a new service called "EvilTokens." The platform specifically targets Microsoft 365 environments by abusing the OAuth 2.0 device code flow—a feature originally designed to allow users to sign into accounts on devices with limited input capabilities, such as smart TVs or IoT hardware.

Unlike traditional credential harvesting, EvilTokens does not steal passwords. Instead, it facilitates a "man-in-the-middle" attack where victims are prompted to enter a legitimate Microsoft-generated code into a malicious portal. Once the victim authenticates, the service captures the resulting access and refresh tokens, granting attackers persistent access to the mailbox even if multi-factor authentication (MFA) is enabled.

Who is affected
Microsoft 365 Tenants
Organizations using default OAuth settings are vulnerable to automated token theft.
Finance Departments
Threat actors are using captured access to conduct Business Email Compromise (BEC) fraud.
Security Operations (SecOps)
Teams must now detect unauthorized "Device Code" authentications across the enterprise.
Remote Employees
Users are being targeted with AI-generated social engineering to solicit authentication codes.

Automation and AI-enabled social engineering

The EvilTokens service represents a shift toward the industrialization of MFA bypass. Microsoft’s Threat Intelligence team reported that the campaign is hitting hundreds of unique organizations daily. The service utilizes AI-augmented templates to craft highly convincing lures that mimic internal IT support notifications or urgent security alerts. These lures direct users to a "verification" page that displays a genuine device code, tricking the user into authorizing the attacker’s application.

Once the token is secured, the EvilTokens backend automatically scans the compromised inbox for financial keywords, active invoice threads, and executive contact lists. This automated reconnaissance allows attackers to initiate BEC fraud within minutes of a successful login. Researchers have noted that the service also includes features to automatically hide the attacker's activity by creating hidden inbox rules that move suspicious replies to the "Archive" or "RSS Feeds" folders.

The move toward Phishing-as-a-Service (PhaaS)

EvilTokens is being marketed on dark web forums as a subscription-based model, lowering the barrier to entry for lower-skilled threat actors. The "kit" handles the hosting of the phishing infrastructure, the rotation of domains to avoid blocklists, and the bypass of standard email security filters. Microsoft has issued an advisory noting that while MFA remains a critical defense, "possession-based" protocols like device code flow are increasingly targeted because they reside outside the scope of traditional password-matching defenses.

Security practitioners are seeing a rise in "AitM" (Adversary-in-the-Middle) techniques that render SMS and TOTP-based MFA less effective. Because the EvilTokens attack occurs during a live session, the "MFA fatigue" or traditional prompt-bombing is replaced by a single, seemingly legitimate interaction. Microsoft has begun rolling out updates to the device code interface to include geographic and application-specific warnings, but the responsibility for restricting this flow currently rests with tenant administrators.


The CyberSignal analysis

Signal 01 — The weaponization of "Convenience" features

Device code flow is a legacy convenience feature that has become a significant enterprise blind spot. Security practitioners should recognize that any authentication flow intended for "low-input" devices is inherently less secure than standard OIDC/SAML flows. In an enterprise environment, the number of users who actually need to sign into M365 on a smart TV is statistically zero, making this an easy surface area to eliminate.

Signal 02 — BEC automation is moving "Upstream"

By integrating automated reconnaissance into the phishing kit itself, EvilTokens shortens the time-to-exploit from days to minutes. This "upstream" automation means that by the time a SecOps team detects an unusual login, the attacker may have already modified payroll details or sent out fraudulent invoices. Detection must move from "post-compromise" to "flow-specific" blocking.

Signal 03 — The end of the "Check the URL" era

Social engineering is evolving past the need for a "fake" login page. Because the user is entering the code into a legitimate Microsoft URL (microsoft.com/devicelogin), traditional user training that focuses on checking the browser's address bar will fail. Security teams must pivot their training to focus on why a user is being asked to perform a specific authentication action, rather than just where they are performing it.


What to do this week

  1. Disable Device Code Flow via Conditional Access. Unless your organization has a documented business need for users to sign in on headless devices, create a Conditional Access policy to block the "Device Code Flow" protocol entirely.
  2. Audit for "Risky" Service Principals. Use the Microsoft Entra ID (formerly Azure AD) portal to search for service principals or applications that have been granted "Office 365 Exchange Online" permissions through a device code login in the last 30 days.
  3. Hunt for specific "EvilTokens" inbox rules. Run a tenant-wide PowerShell script to identify inbox rules that move incoming mail to obscure folders like "Deleted Items," "RSS Subscriptions," or "Conversation History," as these are classic markers of an automated BEC takeover.

Sources

Type Source
Primary Microsoft Security Blog
Reporting BleepingComputer
Reporting The Register
Reporting The Hacker News
Reporting CSO Online

Read more

Illustration of malicious code spreading through a computer system, representing a malware infection.

What Is Malware? Types, How It Spreads, and How to Remove It

A complete guide to malware — the major types, how it spreads and infects devices, the warning signs of an infection, and how to remove and prevent it.

24 May 2026
Illustration of a security team coordinating a response to a cybersecurity incident.

Incident Response: The Complete Guide

A complete guide to incident response — the six-phase lifecycle, the response team, plans and playbooks, frameworks, and the practices that limit breach damage.

23 May 2026
Line-art magnifying glass over a dotted trail connecting a bank, a coin, a house, and a car; the coin carries a single flat red dot.

Europol's Project A.S.S.E.T. Runs Its Largest-Ever Asset-Tracing Week With 31 Countries

Between May 19 and 22, Europol hosted the third and most successful operational week of Project A.S.S.E.T., bringing 31 countries and more than 40 agencies into one room to trace criminal money. The result: hundreds of bank accounts and crypto wallets identified.

23 May 2026
Line-art sign-in window with a user avatar and a check-mark badge; a thin line carries a token icon away to a paper-plane icon, one red dot on the token.

FBI Warns of Kali365: Telegram-Sold Phishing Kit Steals Microsoft 365 Tokens Past MFA

The FBI's IC3 has warned organizations about Kali365, a Telegram-sold phishing-as-a-service kit that runs device-code phishing against Microsoft 365 — stealing the OAuth tokens issued after the victim genuinely passes MFA on Microsoft's real sign-in page.

23 May 2026
The CyberSignal
  • Daily Briefing
  • Weekly Briefing
  • Corrections
  • Privacy Policy
Powered by Ghost