EvilTokens PhaaS Campaign Abuses Railway.com PaaS for Microsoft 365 Device Code Phishing and AiTM Token Replay — Threadlinqs Intelligence
As of 2026-05-30, EvilTokens PhaaS Campaign Abuses Railway.com PaaS for Microsoft 365 Device Code Phishing and AiTM Token Replay is a critical-severity phishing threat attributed to EvilTokens (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-0278 · Severity: CRITICAL · Status: ACTIVE · Category: PHISHING
Attribution: EvilTokens · N/A · FINANCIAL
An active Phishing-as-a-Service (PhaaS) campaign operated by EvilTokens leverages Railway.com PaaS infrastructure to conduct device code phishing and Adversary-in-the-Middle (AiTM) token replay
The EvilTokens Phishing-as-a-Service (PhaaS) platform, first advertised on the NOIRLEGACY GROUP Telegram channel on February 16, 2026, has been weaponizing Railway.com — a legitimate Platform-as-a-Service (PaaS) provider — as clean, disposable infrastructure for a large-scale Microsoft 365 credential theft campaign combining device code phishing and Adversary-in-the-Middle (AiTM) token replay.
The attack chain exploits the OAuth device authorization flow (RFC 8628), a legitimate Microsoft authentication mechanism designed for input-constrained devices such as smart TVs, printers, and kiosk terminals. Attackers generate device codes server-side, then deliver AI-crafted phishing lures — including emails, QR codes, co-opted file-share sites, and custom file download prompts — that direct victims to the legitimate microsoft.com/devicelogin portal. When the victim enters the 8-character code and completes MFA on the real Microsoft login page, the attacker’s backend immediately captures a valid OAuth token set: an access token for immediate resource access and a refresh token valid for up to 90 days. Because the victim authenticates directly with Microsoft, traditional MFA is completely bypassed — no credentials are ever entered on a phishing page.
The EvilTokens platform offers three products: a B2B Sender, an Office 365 Capture Link, and an SMTP Sender. Both the B2B Sender and Capture Link feature AI workflows that bypass email filtering, tailor phishing lures to individual targets, and scan compromised mailboxes for sensitive emails useful in wire fraud or data exfiltration. The platform also provides customers with Open Redirect links to vulnerable domains, through which Cloudflare Workers from the Office 365 Capture Link product steal additional credentials from new victims, creating a self-propagating attack chain.
Railway.com serves as the force multiplier in this campaign. The PaaS platform enables prompt-based deployment of containerized attack infrastructure with automatic TLS, clean IP reputation, and no identity verification — allowing attackers to spin up and tear down credential-harvesting services in minutes. Authentication events originate from a narrow block of Railway IP addresses hosted on Google Cloud Platform (GCP) us-west1 infrastructure. The replay engine rotates through a curated set of user-agent strings that mimic realistic enterprise browser populations to evade uniform UA detection rules.
Post-compromise, attackers leverage stolen tokens for Primary Refresh Token (PRT) acquisition by registering attacker-controlled devices in Entra ID via the Microsoft Authentication Broker client ID. This grants persistent access to organizational resources even after password resets. The campaign targets organizations of all types and sizes — law firms, construction companies, nonprofits, real estate, manufacturing, finance, insurance, healthcare, government, and public safety — across the United States, Canada, Australia, New Zealand, and Germany.
Huntress, in partnership with Flare.io, attributed the Railway-based infrastructure to the EvilTokens PhaaS platform. The campaign shares tactical similarities with Storm-2372, a Russia-linked threat group that has conducted device code phishing since August 2024, though EvilTokens appears to operate as a commercially motivated PhaaS offering rather than a state-sponsored operation. As of March 23, 2026, Huntress had documented approximately 350 compromises and blocked 113 additional attempted compromises, with the campaign showing no signs of deceleration.
Weaknesses (CWE)
CWE-287, CWE-384, CWE-601
Target sectors: government, legal, construction, nonprofit, real-estate, manufacturing, financial, insurance, healthcare, public-safety, technology, defense
Target regions: North America, Europe, Oceania, United States, Canada, Australia, New Zealand, Germany
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, CRITICAL, threat intelligence, cybersecurity, T1566, T1566, T1528, T1539, T1557, T1550, T1656, T1098, T1078, T1114