EvilTokens: AI-Augmented Phishing-as-a-Service Platform Automating Microsoft 365 Device Code Phishing and BEC Fraud — Threadlinqs Intelligence
As of 2026-05-30, EvilTokens: AI-Augmented Phishing-as-a-Service Platform Automating Microsoft 365 Device Code Phishing and BEC Fraud is a high-severity phishing threat attributed to eviltokensadmin (N/A), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0328 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: eviltokensadmin · N/A · FINANCIAL
EvilTokens is a turnkey Phishing-as-a-Service (PhaaS) platform that exploits Microsoft OAuth 2.0 Device Authorization Grant to harvest access and refresh tokens from Microsoft 365 users. The platform
EvilTokens represents a significant evolution in the Phishing-as-a-Service ecosystem by combining Microsoft device code phishing with AI-augmented Business Email Compromise (BEC) automation. First advertised on the NOIRLEGACY GROUP Telegram channel on February 16, 2026, the platform rapidly gained traction among cybercriminals specializing in Adversary-in-the-Middle (AitM) phishing and BEC fraud.
The platform exploits the legitimate OAuth 2.0 Device Authorization Grant flow. Attackers generate device codes using legitimate Microsoft application client IDs, then socially engineer victims into entering these codes on authentic Microsoft login pages (microsoft.com/devicelogin). This bypasses traditional phishing detection because victims authenticate on genuine Microsoft infrastructure. The resulting access tokens (60-90 minute validity) and refresh tokens (long-lived) grant persistent access that survives password resets.
In advanced cases, EvilTokens converts harvested tokens into Primary Refresh Tokens (PRTs), enabling silent single sign-on across all Microsoft 365 applications without requiring passwords or MFA. The platform also leverages Microsoft's Family of Client IDs (FOCI) mechanism for cross-application token exchange escalation.
The AI augmentation layer is the platform's key differentiator. Once tokens are harvested, EvilTokens uses AI to automatically analyze compromised mailboxes via Microsoft Graph API, identify finance-related email threads, and auto-draft convincing BEC emails that mimic the victim's writing style. This dramatically reduces the manual effort required for traditional BEC operations.
The platform operates a centralized backend hosted on Railway.app (AS400940), with affiliate-deployed phishing pages served through Cloudflare Workers. Earlier versions also used Vercel, GitHub Pages, Fastly, and EdgeOne for frontend hosting. Anti-bot protections include User-Agent validation, time-based token hashing (SHA256 of token_secret + Unix timestamp + '_antibot_'), rate limiting, browser fingerprinting, and CAPTCHA verification.
EvilTokens offers multiple products: an Office 365 Capture Link ($1,500 one-time), B2B Sender ($600), SMTP Sender ($1,000), and monthly license ($500). A specialized 'Portal Browser' (ET Browser) sold at $500 enables simultaneous multi-account access to compromised Microsoft 365 tenants. Payment is processed exclusively through NOWPayments cryptocurrency gateway.
Phishing lure diversity is extensive, with templates impersonating DocuSign, Adobe Acrobat Sign, Microsoft Outlook, SharePoint access requests, calendar invites, voicemail notifications, password expiry warnings, OneDrive shared documents, eFax notifications, email quarantine notices, and construction bid documents. Delivery vectors include PDF, HTML, DOCX, XLSX, SVG attachments, QR codes, and hyperlinks.
By March 23, 2026, Huntress had identified compromises across 340+ Microsoft 365 organizations in the United States, Canada, Australia, New Zealand, and Germany, with over 1,000 domains hosting EvilTokens phishing pages. Push Security documented a 37.5x increase in device code phishing pages, attributing the surge largely to EvilTokens adoption. The operator (eviltokensadmin) has announced planned expansion to Gmail and Okta phishing capabilities.
Weaknesses (CWE)
CWE-287, CWE-346, CWE-613
Target sectors: financial, human-resources, transportation, logistics, sales, government, healthcare, technology, legal
Target regions: North America, Europe, Oceania, Middle East, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1593, T1583, T1585, T1588, T1566, T1204, T1098, T1550, T1078