Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365 — Threadlinqs Intelligence
As of 2026-05-30, Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365 is a high-severity phishing threat attributed to Storm-2372 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0323 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Storm-2372 · Russia · FINANCIAL
OAuth 2.0 Device Authorization Grant abuse has surged 37.5x in 2026, driven by EvilTokens and VENOM phishing-as-a-service kits that enable both state-sponsored and financially motivated actors to
A massive escalation in device code phishing campaigns has been observed throughout early 2026, representing a 37.5x increase over baseline detection rates. The surge is primarily driven by the emergence of EvilTokens, a turnkey phishing-as-a-service (PhaaS) platform sold via Telegram, which has democratized access to OAuth 2.0 Device Authorization Grant (RFC 8628) abuse for low-skilled operators.
The attack exploits the legitimate device code authentication flow designed for input-constrained devices. Attackers initiate a POST request to Microsoft's /oauth2/v2.0/devicecode endpoint using legitimate client IDs, receiving a device_code, user_code, and verification_uri. Victims are socially engineered via email, Teams messages, or other channels to visit the legitimate Microsoft device login page and enter the attacker-supplied code. Because authentication occurs on Microsoft's real infrastructure, traditional phishing detection is ineffective. Upon victim authentication, the attacker's backend polls the token endpoint and harvests both short-lived access tokens (60-90 minutes) and long-lived refresh tokens enabling persistent account access.
Critically, this technique bypasses all forms of MFA including phishing-resistant methods such as passkeys, because the attack targets the authorization layer post-authentication. Tokens remain valid even after password resets. Using the Microsoft Authentication Broker client ID, attackers can obtain refresh tokens to register attacker-controlled devices in Entra ID, acquire Primary Refresh Tokens (PRTs), and achieve persistent organizational access.
EvilTokens, the dominant kit, features a Cloudflare Workers frontend with Railway.com backend infrastructure, anti-bot protection (X-Antibot-Token header), popup-based device code entry for reduced friction, email harvesting, reconnaissance capabilities, a built-in webmail interface, and AI-powered BEC automation. The operator (Telegram handle: _eviltokensadmin_) has announced plans to expand targeting to Gmail and Okta. VENOM, a closed-source competitor, offers both device code phishing and Adversary-in-the-Middle (AiTM) capabilities.
Push Security and Sekoia have identified 11 distinct phishing kit families: EvilTokens (ANTIBOT), SHAREFILE, CLURE, LINKID, AUTHOV, DOCUPOLL, FLOW_TOKEN, PAPRIKA, DCSTATUS, DOLCE, and VENOM. These kits leverage diverse hosting infrastructure including Cloudflare Workers, Vercel, GitHub Pages, AWS S3, Microsoft PowerApps, Tencent Cloud, and DigitalOcean, with Railway.com serving as the primary backend for EvilTokens operations.
The campaign builds on prior device code phishing activity by Storm-2372, a Russia-aligned threat actor tracked by Microsoft since August 2024, and associated groups APT29, UTA0304, UTA0307, and UNK_AcademicFlare. The current wave has expanded beyond state-sponsored espionage to include financially motivated cybercriminals conducting BEC campaigns across construction, nonprofits, real estate, manufacturing, financial services, healthcare, legal, and government sectors.
Evasion techniques include abuse of legitimate security vendor redirect services (Cisco, Trend Micro, Mimecast), multi-hop redirect chains, anti-bot protection, disabled developer tools, and infinite debugger loops. Social engineering lures impersonate Microsoft Teams, SharePoint, DocuSign, Citrix ShareFile, Adobe, and construction bid platforms.
Weaknesses (CWE)
CWE-287, CWE-294, CWE-346
Target sectors: government, financial, healthcare, legal, construction, nonprofit, real-estate, manufacturing, defense, telecommunications, energy, higher-education
Target regions: North America, Europe, Oceania, Middle East, South Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1566, T1566, T1621, T1528, T1550, T1098, T1078, T1114, T1583, T1588