Threat reportPhishingTL-2026-0328
EvilTokens: AI-Augmented Phishing-as-a-Service Platform Automating Microsoft 365 Device Code Phishing and BEC Fraud
EvilTokens: AI-Augmented Phishing-as-a-Service Platform (TL-2026-0328), also tracked as EvilTokens PhaaS, is a high-severity phishing campaign, first published 2026-04-07. It has no confirmed attribution, affects Microsoft Microsoft 365, maps to 18 MITRE ATT&CK techniques (T1071, T1078, T1098), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-0328
- Threat ID
- TL-2026-0328
- Also known as
- EvilTokens PhaaS, ET Browser Campaign, Railway Device Code Phishing Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial, human-resources, transportation, logistics, sales, government, healthcare, technology, legal
- Target regions
- North America, Europe, Oceania, Middle East, Asia
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in EvilTokens: AI-Augmented Phishing-as-a-Service Platform
Malware and tooling: EvilTokens B2B Sender, EvilTokens Office 365 Capture Link, EvilTokens Portal Browser (ET Browser), EvilTokens SMTP Sender, Microsoft Graph API
How EvilTokens: AI-Augmented Phishing-as-a-Service Platform works
EvilTokens is a turnkey Phishing-as-a-Service (PhaaS) platform that exploits Microsoft OAuth 2.0 Device Authorization Grant to harvest access and refresh tokens from Microsoft 365 users. The platform integrates AI-powered mailbox analysis and automated BEC email drafting, enabling approximately 280 affiliates to compromise 340+ organizations across five countries since its launch in February 2026.
EvilTokens represents a significant evolution in the Phishing-as-a-Service ecosystem by combining Microsoft device code phishing with AI-augmented Business Email Compromise (BEC) automation. First advertised on the NOIRLEGACY GROUP Telegram channel on February 16, 2026, the platform rapidly gained traction among cybercriminals specializing in Adversary-in-the-Middle (AitM) phishing and BEC fraud.
The platform exploits the legitimate OAuth 2.0 Device Authorization Grant flow. Attackers generate device codes using legitimate Microsoft application client IDs, then socially engineer victims into entering these codes on authentic Microsoft login pages (microsoft.com/devicelogin). This bypasses traditional phishing detection because victims authenticate on genuine Microsoft infrastructure. The resulting access tokens (60-90 minute validity) and refresh tokens (long-lived) grant persistent access that survives password resets.
In advanced cases, EvilTokens converts harvested tokens into Primary Refresh Tokens (PRTs), enabling silent single sign-on across all Microsoft 365 applications without requiring passwords or MFA. The platform also leverages Microsoft's Family of Client IDs (FOCI) mechanism for cross-application token exchange escalation.
The AI augmentation layer is the platform's key differentiator. Once tokens are harvested, EvilTokens uses AI to automatically analyze compromised mailboxes via Microsoft Graph API, identify finance-related email threads, and auto-draft convincing BEC emails that mimic the victim's writing style. This dramatically reduces the manual effort required for traditional BEC operations.
The platform operates a centralized backend hosted on Railway.app (AS400940), with affiliate-deployed phishing pages served through Cloudflare Workers. Earlier versions also used Vercel, GitHub Pages, Fastly, and EdgeOne for frontend hosting. Anti-bot protections include User-Agent validation, time-based token hashing (SHA256 of token_secret + Unix timestamp + '_antibot_'), rate limiting, browser fingerprinting, and CAPTCHA verification.
EvilTokens offers multiple products: an Office 365 Capture Link ($1,500 one-time), B2B Sender ($600), SMTP Sender ($1,000), and monthly license ($500). A specialized 'Portal Browser' (ET Browser) sold at $500 enables simultaneous multi-account access to compromised Microsoft 365 tenants. Payment is processed exclusively through NOWPayments cryptocurrency gateway.
Phishing lure diversity is extensive, with templates impersonating DocuSign, Adobe Acrobat Sign, Microsoft Outlook, SharePoint access requests, calendar invites, voicemail notifications, password expiry warnings, OneDrive shared documents, eFax notifications, email quarantine notices, and construction bid documents. Delivery vectors include PDF, HTML, DOCX, XLSX, SVG attachments, QR codes, and hyperlinks.
By March 23, 2026, Huntress had identified compromises across 340+ Microsoft 365 organizations in the United States, Canada, Australia, New Zealand, and Germany, with over 1,000 domains hosting EvilTokens phishing pages. Push Security documented a 37.5x increase in device code phishing pages, attributing the surge largely to EvilTokens adoption. The operator (eviltokensadmin) has announced planned expansion to Gmail and Okta phishing capabilities.
MITRE ATT&CK techniques used in TL-2026-0328
command-and-control
T1071 Application Layer Protocol; T1102 Web Service
defense-evasion
persistence
collection
T1114 Email Collection; T1530 Data from Cloud Storage
execution
credential-access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie
lateral-movement
T1550 Use Alternate Authentication Material
initial-access
exfiltration
T1567 Exfiltration Over Web Service
resource-development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1588 Obtain Capabilities
reconnaissance
T1593 Search Open Websites/Domains; T1598 Phishing for Information
impact
Affected products and versions in EvilTokens: AI-Augmented Phishing-as-a-Service Platform
- Microsoft — Microsoft 365
Vulnerable versions: All current versions - Microsoft — Azure Active Directory / Entra ID
Vulnerable versions: All tenants with Device Code Flow enabled - Microsoft — Outlook / Exchange Online
Vulnerable versions: All current versions - Microsoft — OneDrive / SharePoint Online
Vulnerable versions: All current versions - Microsoft — Microsoft Teams
Vulnerable versions: All current versions
Remediation for EvilTokens: AI-Augmented Phishing-as-a-Service Platform
Immediate actions
- Block Railway.app CIDR ranges at network perimeter: 152.55.176.0/20, 162.220.232.0/22, 208.77.244.0/22, 66.33.22.0/23, 69.46.46.0/24, 69.9.164.0/22
- Audit Azure AD sign-in logs for device code authentication events from Railway IP ranges
- Revoke all active refresh tokens for accounts showing suspicious device code authentications
- Block known EvilTokens backend IPs: 162.220.232.71, 71.11.42.193, 72.218.25.107
- Review Microsoft 365 Conditional Access policies to restrict device code flow
Workarounds
- Disable OAuth Device Code Flow in Azure AD if not required for legitimate business use
- Restrict allowed OAuth applications via Azure AD application consent policies
- Enable Continuous Access Evaluation (CAE) for near-real-time token revocation
- Configure Microsoft Defender for Cloud Apps to detect anomalous token usage
Longer-term hardening
- Implement Conditional Access policies blocking or restricting OAuth Device Code Flow (device_code grant type)
- Deploy browser-based phishing detection that warns on device code login URLs
- Enable Microsoft 365 token protection policies to bind tokens to specific devices
- Implement anomaly detection for Microsoft Graph API access patterns indicating mailbox reconnaissance
- Deploy email security controls detecting BEC patterns in outbound mail
- Conduct user awareness training specifically covering device code phishing lures
Weaknesses (CWE) in EvilTokens: AI-Augmented Phishing-as-a-Service Platform
Timeline of EvilTokens: AI-Augmented Phishing-as-a-Service Platform
- EvilTokens first advertised on NOIRLEGACY GROUP Telegram channel with initial product offerings
- First compromises from Railway.app infrastructure observed by Huntress SOC
- Additional early compromise wave detected from Railway infrastructure
- Huntress SOC surfaces anomalous authentication pattern across dozens of organizations simultaneously, revealing device code phishing campaign
- Sekoia Threat Detection and Research team identifies EvilTokens via Telegram PhaaS advertisement and begins investigation
- EvilTokens private customer group reaches approximately 280 subscribers on Telegram
- Huntress publishes blog attributing Railway.app PaaS abuse to EvilTokens PhaaS platform
- Huntress confirms 340+ Microsoft 365 organizations compromised across US, Canada, Australia, New Zealand, and Germany. Over 1,000 domains hosting EvilTokens phishing pages. 113 additional compromises blocked.
- Sekoia publishes Part 1 research on EvilTokens device code phishing infrastructure and TLP:AMBER FLINT report distributed to customers
- Push Security documents 37.5x increase in device code phishing pages, identifying at least 11 distinct phishing kits including EvilTokens as primary driver
- Sekoia publishes Part 2 detailing AI-augmented BEC automation features, mailbox reconnaissance, and auto-drafting capabilities
- As of 2026-05-29, EvilTokens PhaaS remains actively operational with no takedown, arrest, or infrastructure seizure; CSA (2026-05-20) and Help Net Security (2026-05-22) still cite it as live and continuously upgraded. It abuses Microsoft's by-design OAuth device code flow (no patch, MFA-bypassing), and device code phishing keeps proliferating alongside the newer Kali365 kit.
Sources cited for EvilTokens: AI-Augmented Phishing-as-a-Service Platform
- Sekoia TDR - EvilTokens Part 2: AI-augmented PhaaS for BEC fraud
- Sekoia TDR - EvilTokens Part 1: Device code phishing as-a-service
- Huntress - Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure
- BleepingComputer - New EvilTokens service fuels Microsoft device code phishing attacks
- Push Security - Analysing the rise in device code phishing attacks in 2026
- The Hacker News - Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries
- CyberNewsAI - EvilTokens PhaaS Abuses Railway PaaS for M365 Attacks
- CSO Online - EvilTokens abuses Microsoft device code flow for account takeovers
- Huntress Support - 2026-March Railway Exploit Guidance
- Help Net Security - EvilTokens ramps up device code phishing targeting Microsoft 365 users
Detection coverage for TL-2026-0328
As of 2026-04-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0328 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.