Threat reportPhishingTL-2026-0328

EvilTokens: AI-Augmented Phishing-as-a-Service Platform Automating Microsoft 365 Device Code Phishing and BEC Fraud

highACTIVE

EvilTokens: AI-Augmented Phishing-as-a-Service Platform (TL-2026-0328), also tracked as EvilTokens PhaaS, is a high-severity phishing campaign, first published 2026-04-07. It has no confirmed attribution, affects Microsoft Microsoft 365, maps to 18 MITRE ATT&CK techniques (T1071, T1078, T1098), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-0328

Threat ID
TL-2026-0328
Also known as
EvilTokens PhaaS, ET Browser Campaign, Railway Device Code Phishing Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial, human-resources, transportation, logistics, sales, government, healthcare, technology, legal
Target regions
North America, Europe, Oceania, Middle East, Asia
Detection rules
9
Indicators of compromise
30

Malware and tooling in EvilTokens: AI-Augmented Phishing-as-a-Service Platform

Malware and tooling: EvilTokens B2B Sender, EvilTokens Office 365 Capture Link, EvilTokens Portal Browser (ET Browser), EvilTokens SMTP Sender, Microsoft Graph API

How EvilTokens: AI-Augmented Phishing-as-a-Service Platform works

EvilTokens is a turnkey Phishing-as-a-Service (PhaaS) platform that exploits Microsoft OAuth 2.0 Device Authorization Grant to harvest access and refresh tokens from Microsoft 365 users. The platform integrates AI-powered mailbox analysis and automated BEC email drafting, enabling approximately 280 affiliates to compromise 340+ organizations across five countries since its launch in February 2026.

EvilTokens represents a significant evolution in the Phishing-as-a-Service ecosystem by combining Microsoft device code phishing with AI-augmented Business Email Compromise (BEC) automation. First advertised on the NOIRLEGACY GROUP Telegram channel on February 16, 2026, the platform rapidly gained traction among cybercriminals specializing in Adversary-in-the-Middle (AitM) phishing and BEC fraud.

The platform exploits the legitimate OAuth 2.0 Device Authorization Grant flow. Attackers generate device codes using legitimate Microsoft application client IDs, then socially engineer victims into entering these codes on authentic Microsoft login pages (microsoft.com/devicelogin). This bypasses traditional phishing detection because victims authenticate on genuine Microsoft infrastructure. The resulting access tokens (60-90 minute validity) and refresh tokens (long-lived) grant persistent access that survives password resets.

In advanced cases, EvilTokens converts harvested tokens into Primary Refresh Tokens (PRTs), enabling silent single sign-on across all Microsoft 365 applications without requiring passwords or MFA. The platform also leverages Microsoft's Family of Client IDs (FOCI) mechanism for cross-application token exchange escalation.

The AI augmentation layer is the platform's key differentiator. Once tokens are harvested, EvilTokens uses AI to automatically analyze compromised mailboxes via Microsoft Graph API, identify finance-related email threads, and auto-draft convincing BEC emails that mimic the victim's writing style. This dramatically reduces the manual effort required for traditional BEC operations.

The platform operates a centralized backend hosted on Railway.app (AS400940), with affiliate-deployed phishing pages served through Cloudflare Workers. Earlier versions also used Vercel, GitHub Pages, Fastly, and EdgeOne for frontend hosting. Anti-bot protections include User-Agent validation, time-based token hashing (SHA256 of token_secret + Unix timestamp + '_antibot_'), rate limiting, browser fingerprinting, and CAPTCHA verification.

EvilTokens offers multiple products: an Office 365 Capture Link ($1,500 one-time), B2B Sender ($600), SMTP Sender ($1,000), and monthly license ($500). A specialized 'Portal Browser' (ET Browser) sold at $500 enables simultaneous multi-account access to compromised Microsoft 365 tenants. Payment is processed exclusively through NOWPayments cryptocurrency gateway.

Phishing lure diversity is extensive, with templates impersonating DocuSign, Adobe Acrobat Sign, Microsoft Outlook, SharePoint access requests, calendar invites, voicemail notifications, password expiry warnings, OneDrive shared documents, eFax notifications, email quarantine notices, and construction bid documents. Delivery vectors include PDF, HTML, DOCX, XLSX, SVG attachments, QR codes, and hyperlinks.

By March 23, 2026, Huntress had identified compromises across 340+ Microsoft 365 organizations in the United States, Canada, Australia, New Zealand, and Germany, with over 1,000 domains hosting EvilTokens phishing pages. Push Security documented a 37.5x increase in device code phishing pages, attributing the surge largely to EvilTokens adoption. The operator (eviltokensadmin) has announced planned expansion to Gmail and Okta phishing capabilities.

MITRE ATT&CK techniques used in TL-2026-0328

command-and-control

T1071 Application Layer Protocol; T1102 Web Service

defense-evasion

T1078 Valid Accounts

persistence

T1098 Account Manipulation

collection

T1114 Email Collection; T1530 Data from Cloud Storage

execution

T1204 User Execution

credential-access

T1528 Steal Application Access Token; T1539 Steal Web Session Cookie

lateral-movement

T1550 Use Alternate Authentication Material

initial-access

T1566 Phishing

exfiltration

T1567 Exfiltration Over Web Service

resource-development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities

reconnaissance

T1593 Search Open Websites/Domains; T1598 Phishing for Information

impact

T1657 Financial Theft

Affected products and versions in EvilTokens: AI-Augmented Phishing-as-a-Service Platform

  • Microsoft — Microsoft 365
    Vulnerable versions: All current versions
  • Microsoft — Azure Active Directory / Entra ID
    Vulnerable versions: All tenants with Device Code Flow enabled
  • Microsoft — Outlook / Exchange Online
    Vulnerable versions: All current versions
  • Microsoft — OneDrive / SharePoint Online
    Vulnerable versions: All current versions
  • Microsoft — Microsoft Teams
    Vulnerable versions: All current versions

Remediation for EvilTokens: AI-Augmented Phishing-as-a-Service Platform

Immediate actions

  • Block Railway.app CIDR ranges at network perimeter: 152.55.176.0/20, 162.220.232.0/22, 208.77.244.0/22, 66.33.22.0/23, 69.46.46.0/24, 69.9.164.0/22
  • Audit Azure AD sign-in logs for device code authentication events from Railway IP ranges
  • Revoke all active refresh tokens for accounts showing suspicious device code authentications
  • Block known EvilTokens backend IPs: 162.220.232.71, 71.11.42.193, 72.218.25.107
  • Review Microsoft 365 Conditional Access policies to restrict device code flow

Workarounds

  • Disable OAuth Device Code Flow in Azure AD if not required for legitimate business use
  • Restrict allowed OAuth applications via Azure AD application consent policies
  • Enable Continuous Access Evaluation (CAE) for near-real-time token revocation
  • Configure Microsoft Defender for Cloud Apps to detect anomalous token usage

Longer-term hardening

  • Implement Conditional Access policies blocking or restricting OAuth Device Code Flow (device_code grant type)
  • Deploy browser-based phishing detection that warns on device code login URLs
  • Enable Microsoft 365 token protection policies to bind tokens to specific devices
  • Implement anomaly detection for Microsoft Graph API access patterns indicating mailbox reconnaissance
  • Deploy email security controls detecting BEC patterns in outbound mail
  • Conduct user awareness training specifically covering device code phishing lures

Weaknesses (CWE) in EvilTokens: AI-Augmented Phishing-as-a-Service Platform

CWE-287, CWE-346, CWE-613

Timeline of EvilTokens: AI-Augmented Phishing-as-a-Service Platform

  • EvilTokens first advertised on NOIRLEGACY GROUP Telegram channel with initial product offerings
  • First compromises from Railway.app infrastructure observed by Huntress SOC
  • Additional early compromise wave detected from Railway infrastructure
  • Huntress SOC surfaces anomalous authentication pattern across dozens of organizations simultaneously, revealing device code phishing campaign
  • Sekoia Threat Detection and Research team identifies EvilTokens via Telegram PhaaS advertisement and begins investigation
  • EvilTokens private customer group reaches approximately 280 subscribers on Telegram
  • Huntress publishes blog attributing Railway.app PaaS abuse to EvilTokens PhaaS platform
  • Huntress confirms 340+ Microsoft 365 organizations compromised across US, Canada, Australia, New Zealand, and Germany. Over 1,000 domains hosting EvilTokens phishing pages. 113 additional compromises blocked.
  • Sekoia publishes Part 1 research on EvilTokens device code phishing infrastructure and TLP:AMBER FLINT report distributed to customers
  • Push Security documents 37.5x increase in device code phishing pages, identifying at least 11 distinct phishing kits including EvilTokens as primary driver
  • Sekoia publishes Part 2 detailing AI-augmented BEC automation features, mailbox reconnaissance, and auto-drafting capabilities
  • As of 2026-05-29, EvilTokens PhaaS remains actively operational with no takedown, arrest, or infrastructure seizure; CSA (2026-05-20) and Help Net Security (2026-05-22) still cite it as live and continuously upgraded. It abuses Microsoft's by-design OAuth device code flow (no patch, MFA-bypassing), and device code phishing keeps proliferating alongside the newer Kali365 kit.

Sources cited for EvilTokens: AI-Augmented Phishing-as-a-Service Platform

Detection coverage for TL-2026-0328

As of 2026-04-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0328 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats