Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

EvilTokens

4
Global rank
3 infographic chevron month
Month rank
2 infographic chevron week
Week rank
0
IOCs

EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.

Phishingkit
Type
Unknown
Origin
Unknown
First seen
29 August, 2026
Last seen

How to analyze EvilTokens with ANY.RUN

Type
Unknown
Origin
Unknown
First seen
29 August, 2026
Last seen

IOCs

IP addresses
128.24.231.65
88.221.169.205
20.67.186.184
184.86.251.19
13.107.246.44
88.221.169.152
150.171.109.100
185.104.29.104
150.171.109.101
48.209.138.168
2.16.241.224
96.6.17.223
48.209.133.15
40.126.32.133
20.50.201.204
150.171.27.11
104.18.22.222
142.251.14.132
20.119.128.20
150.171.28.11
Hashes
db39694c444ea393569aafb2cd8ec865006f3df9ecbcb7996e7b219b30ec366d
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
35872a3343d4b4768fe4702a8dc18b749933e81210db13466ad172bd2880f6eb
de6d7b7c2427ec4e738407d7834b71941f69166b030355e00f325ff1391df5a1
cf26310b073b0891996ecd761c6cb53f00193dee524213a9fb34225d636ec4b7
Domains
edge.microsoft.com
api.edgeoffer.microsoft.com
slscr.update.microsoft.com
edge-mobile-static.azureedge.net
www.microsoft.com
login.live.com
go.microsoft.com
settings-win.data.microsoft.com
www.bing.com
microsoft.com
update.googleapis.com
xpaywalletcdn.azureedge.net
eu-mobile.events.data.microsoft.com
static.edge.microsoftapp.net
aadcdn.msauth.net
login.microsoft.com
fonts.googleapis.com
login.microsoftonline.com
aadcdn.msftauth.net
ocsp.digicert.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:r-8zybns9re4rbydml-5micfrsr9ij2kuilaxxtaeu8&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://griponmash.eu/efi5dfuyfd56f7oh99/
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://griponmash.eu/favicon.ico
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://griponmash.eu/wp-content/uploads/2024/01/fav-icon.png
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d253%2526e%253d1
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://update.googleapis.com/service/update2/json?cup2key=14:qruses8agnpmukohtg2iamn_zfyjwdbfvw0ja61te5m&cup2hreq=c82d95b4694923139f9ec66793a50013f976d453c456b1f7a2cb644a22f841cb
https://clients2.googleusercontent.com/crx/blobs/abe5cl6a_jaanxapcjclooga79zaaqm3tadaaxpzgbj_5tef2gcwgawlwvojctwjy-62xnz5nkplhywefhkfca7ve1mtom8zrfv598knndu2neqdltxpxs0ljjjkmozedq0axlka5z-i_mcpvgwijs_fx-_dkkqdwg3y/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_109_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3153
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 8509
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11265
comments 0

EvilTokens: How AI-Powered Device Code Phishing Is Making Business Email Compromise Unstoppable

Key Takeaways

  1. EvilTokens bypasses MFA by abusing Microsoft's own device code OAuth flow, obtaining valid tokens without password theft.

  2. As a PhaaS kit sold on Telegram, it democratizes sophisticated attacks, enabling rapid scaling with minimal technical skill.

  3. AI-powered features generate convincing lures and automate BEC, increasing both volume and success rates.

  4. Persistent refresh tokens allow long-term access, device registration, and silent authentication across M365 services.

  5. Organizations in finance, government, healthcare, and other M365-heavy sectors are prime targets globally.

  6. Security teams can query ANY.RUN's Threat Intelligence Lookup for known EvilTokens domains, URLs, and infrastructure indicators in real time — enriching SIEM alerts, hunting for campaign IOCs, and staying ahead of the platform's rapid infrastructure rotation before damage is done.

destinationIP:"75.98.162.49".

Malicious IP linked to EvilTokens Malicious IP linked to EvilTokens

  1. ANY.RUN's Interactive Sandbox lets analysts safely detonate EvilTokens lures. Submit suspicious PDFs, HTML documents, and phishing URLs from EvilTokens campaigns to observe behavior, capture network IOCs, and generate detection signatures.

View analysis session

Eviltokens phishing analysis in Interactive Sandbox EvilTokens phishing analysis in Interactive Sandbox

What is EvilTokens Malware?

EvilTokens is a turnkey, productized PhaaS platform sold to criminal affiliates via Telegram. Unlike conventional phishing kits that replicate Microsoft login pages or intercept credentials in transit, EvilTokens abuses the legitimate OAuth 2.0 Device Authorization Grant (a Microsoft authentication flow designed for devices with limited input capabilities, such as smart TVs, IoT sensors, and printers) to steal valid OAuth tokens after the victim has completed a fully legitimate MFA challenge on Microsoft's real infrastructure.

First identified by Sekoia's Threat Detection & Research (TDR) team in early March 2026, EvilTokens had already been circulating in underground cybercrime communities since mid-February 2026. Its operator, known as eviltokensadmin, advertised the kit in private Telegram channels frequented by threat actors specializing in Adversary-in-the-Middle (AitM) phishing and BEC fraud.

What sets EvilTokens apart from the crowded phishing kit marketplace is its comprehensive, full-lifecycle attack package. Beyond the core phishing module, the platform provides affiliates with:

  • Ready-made phishing page templates impersonating services like Adobe Acrobat, DocuSign, SharePoint, OneDrive, and Microsoft itself.

  • Token weaponization tools to immediately leverage stolen OAuth credentials.

  • Email harvesting and inbox analysis powered by AI, using Meta's LLaMA model to automatically prioritize high-value conversations.

  • A built-in webmail client, internally branded "MailVault," styled to mimic Outlook, enabling attackers to read, compose, and send emails directly from compromised inboxes.

  • Reconnaissance via the Microsoft Graph API, including automatic detection of Exchange and Global Administrator accounts (flagged with a crown icon) to enable privilege escalation.

  • Keyword alerting via Telegram, so attackers are instantly notified when terms like "invoice," "wire transfer," or "payment" appear in harvested mailboxes.

  • AI-generated phishing lures, with LLMs crafting personalized and contextually convincing social engineering messages at scale.

  • Multi-tenant SaaS architecture, giving each affiliate their own isolated environment, unique credentials, and a pool of compromised accounts

The platform operates through fully featured Telegram bots and a Vue.js admin panel marketed externally as "MailVault — Enterprise Email Management Platform" to disguise its true nature. It is under continuous development, with the operator publicly announcing plans to expand support to Gmail and Okta phishing in the near future.

Researchers at Abnormal AI assessed with high confidence that EvilTokens' underlying code was likely AI-generated, reflecting a broader and alarming trend of AI accelerating both the development and operation of criminal phishing infrastructure.

How EvilTokens Threatens Businesses and Organizations

EvilTokens targets the identity layer — the very fabric of modern enterprise security —without triggering typical credential-based alerts.

Key risks include:

  • MFA Bypass: Instead of stealing passwords, attackers obtain valid tokens, effectively sidestepping MFA protections.

  • Persistent Access: Refresh tokens allow long-term access even after password resets.

  • Business Email Compromise (BEC): Attackers gain control of corporate email, enabling fraud, invoice manipulation, and executive impersonation.

  • Data Exfiltration: Access extends to email, cloud storage, Teams, and SSO-connected apps.

  • Stealth and Evasion: Because authentication occurs through legitimate Microsoft pages, detection becomes significantly harder.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Which Industries Are Most at Risk?

EvilTokens is opportunistic, but not random. It gravitates toward roles with access and authority.

Most targeted sectors:

  • Finance & Banking (payment authorization, fraud potential);

  • Healthcare (sensitive data + weaker identity controls);

  • Government & Public Sector (high-value intelligence);

  • Technology & SaaS companies (cloud-heavy environments);

  • Logistics & Supply Chain (invoice and partner fraud vectors).

High-risk roles include:

  • CFOs and finance teams

  • HR and payroll staff

  • Executives and decision-makers

Campaigns have already impacted hundreds of organizations globally across industries. The most impacted countries as of late March 2026 include the United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates — essentially any country with a significant concentration of Microsoft 365 enterprise users and active cross-border financial flows.

EvilTokens’ Malware Infection Vector and Spread

EvilTokens' delivery chain is engineered for maximum deception at every stage.

Stage 1 — Initial lure delivery. Phishing emails are sent from previously compromised legitimate accounts — real Microsoft 365 or Google Workspace mailboxes belonging to other victims. This means the sender passes all standard email authentication checks: SPF PASS, DKIM PASS, and DMARC PASS. The lure emails impersonate routine business communications: shared document notifications from OneDrive or SharePoint, DocuSign signing requests, invoice approvals, calendar invites, or HR announcements.

Attachments may be PDF, HTML, DOCX, XLSX, or SVG files containing either a QR code or a hyperlink leading to the phishing infrastructure.

Stage 2 — Bot filter gate. Links in lure emails point not to EvilTokens infrastructure directly but to compromised legitimate websites where a PHP bot filter validates whether the visitor is a real browser executing JavaScript. Automated sandbox crawlers and security scanners that lack JavaScript are trapped in a meta refresh loop and never reach the payload, providing a layer of detection evasion.

Stage 3 — Identity verification gate page. Legitimate visitors are redirected to a gate page (versioned, branded "Identity Verification") that collects the target's email address and passes it to a Cloudflare Worker, further obscuring the backend infrastructure.

Stage 4 — Phishing page. The victim is presented with a page impersonating a trusted service (Adobe Acrobat, DocuSign, Microsoft). The page displays a legitimate Microsoft device code generated in real time by EvilTokens' C2 server calling Microsoft's /devicecode endpoint alongside instructions to "verify identity" by visiting Microsoft's real device login page and entering the displayed code.

Stage 5 — Token harvest. When the victim authenticates on Microsoft's genuine login page (completing real MFA in the process), EvilTokens' C2 simultaneously polls Microsoft's /token endpoint to collect the resulting OAuth access token and refresh token. The attacker now controls the session.

Stage 6 — Lateral spread. With access to the victim's mailbox and contacts, attackers identify further high-value targets within the organization and among its business partners, launching new lure campaigns from the now-compromised legitimate account, perpetuating the cycle.

How Does EvilTokens Function?

Once tokens are harvested, EvilTokens provides a full post-compromise operational suite delivered through the MailVault admin panel.

Token weaponization. The short-lived access token (valid 60–90 minutes) is used immediately to extract emails from Exchange Online, documents from SharePoint and OneDrive, and conversation history from Microsoft Teams. The refresh token (valid 90 days, rolling) is used to silently obtain new access tokens, maintaining persistent access to the account without re-authentication.

Privilege escalation detection. JWT claim parsing within the MailVault panel automatically identifies whether the compromised account holds Exchange Administrator or Global Administrator roles flagging these high-privilege accounts so affiliates know to prioritize them for deeper exploitation.

AI-powered email analysis. Using Meta's LLaMA model integrated into the platform, EvilTokens automatically analyzes harvested emails to surface high-value threads: financial conversations, invoice chains, payment instructions, and sensitive business discussions.

Keyword alerting. A Telegram-integrated keyword scanner notifies affiliates in real time when target terms appear in harvested mailboxes, enabling rapid exploitation of time-sensitive financial transactions.

BEC operations via MailVault. The built-in webmail client allows attackers to read all emails in a compromised inbox, download attachments, and compose and send messages that genuinely originate from the victim's account. Attackers can insert themselves into ongoing financial threads, redirect payments, impersonate executives, or exfiltrate sensitive documents without any technical complexity.

Persistence and device registration. Refresh tokens can be used to register an attacker-controlled device in Entra ID, granting even more durable access that persists beyond password resets unless explicitly revoked at the device level.

AI-generated lures. LLMs integrated into the platform generate contextually tailored phishing messages for new targets, varying content across recipients to evade signature-based detection and reduce campaign fatigue.

How Can Businesses Proactively Protect Against EvilTokens Malware?

Defending against a threat as technically sophisticated and rapidly evolving as EvilTokens requires moving from reactive incident response to proactive, intelligence-driven security.

ANY.RUN's Threat Intelligence Lookup gives security teams direct, real-time access to threat data collected from millions of malware analysis sessions in ANY.RUN's Interactive Sandbox. For EvilTokens specifically, TI Lookup enables organizations to:

  • Query known EvilTokens indicators of compromise and instantly determine whether any of these indicators have appeared in their environment or email logs.
  • Track infrastructure evolution in real time. TI Lookup surfaces newly observed indicators as they are processed, enabling defenders to stay ahead of infrastructure changes rather than chasing yesterday's IOCs.

threatName:"eviltokens".

Fresh EvilTokens IOCs Fresh EvilTokens IOCs found in TI Lookup

  • Hunt for EvilTokens-linked network artifacts — such as requests to Microsoft's /devicecode and /token endpoints combined with suspicious referral chains — that may indicate active campaigns targeting the organization.
  • Contextualize alerts. When a SIEM or EDR fires on a suspicious domain or URL, TI Lookup provides immediate context: is this known EvilTokens infrastructure? What campaigns is it linked to? What was observed in sandbox analysis?

You can start from looking up the threat by name to get a selection of recent sandbox analysis sessions featuring EvilTokens attacks and pivot your research and hunting from there:

threatName:"eviltokens".

EvilTokens sandbox analyses EvilTokens sandbox analyses found via TI Lookup

Additional Measures:

  • Enforcing Conditional Access policies to restrict or monitor device code flows.

  • User education on unusual "enter code on Microsoft login" requests.

  • Monitoring for anomalous token usage or new device registrations in Entra ID.

  • Advanced email filtering for AI-generated lures and attachment-based phishing.

  • Implementing least-privilege access and regular token reviews.

  • Behavioral analytics to detect post-compromise activity like unusual Graph API calls.

Sandbox Analysis of EvilTokens Sample

See the detonation of an EvilTokens sample

EvilTokens attack chain in the sandbox EvilTokens attack chain in the sandbox

The attack often begins with a landing page impersonating DocuSign, prompting the user to “Review Document.” The victim is shown a verification code and instructed to copy it.

Key red flag: this is not a real DocuSign signing workflow. It is a scripted sequence:

  • Copy the verification code,

  • Click “Continue to Microsoft”,

  • Paste the code into Microsoft’s device login page.

The address bar typically shows a *.workers.dev domain instead of a legitimate DocuSign domain.

A Microsoft window then opens at login.microsoftonline.com/…/deviceauth, showing the form “Enter code to allow access.” The user enters the same code they were shown on the fake page. This action takes place on a legitimate Microsoft domain, even displaying Microsoft’s own warning: “Do not enter codes from sources you don’t trust.”

Fake verification granting access to external client Fake verification granting access to external client

The following screen states: “You’re signing in to Microsoft Office on another device…” From the victim’s perspective, the process still appears legitimate. In reality, they are approving access for an external client controlled by the attacker, not verifying the document they originally clicked.

The key point is: the user never enters their password on a fake site. Instead, they are guided through legitimate Microsoft infrastructure and manually transfer a code.

How Automatic SSL Decryption Ensures Instant Detection

From an investigation standpoint, these phishing pages often rely on JavaScript loaders and encrypted HTTPS traffic to hide the real workflow from traditional scanners.

This is where SSL decryption in the ANY.RUN Sandbox becomes critical. By extracting TLS encryption keys directly from process memory and decrypting HTTPS traffic during execution, the sandbox reveals the hidden scripts, API requests, and attacker infrastructure involved in the phishing flow.

SSL decryption allows Suricata IDS rules to detect malicious encrypted traffic SSL decryption allows Suricata IDS rules to detect malicious encrypted traffic

In this case, SSL decryption exposed the malicious JavaScript responsible for orchestrating the device authorization process and revealed high-confidence network indicators used by the phishing kit. Among them were specific API requests such as /api/device/start and /api/device/status/, along with a distinctive X-Antibot-Token header used in communication with the backend.

Traffic decrypted with SSL decryption

Traffic decrypted with SSL decryption Traffic decrypted with SSL decryption

When these artifacts appear in HTTP requests to non-legitimate hosts, they become high-signal network IOCs that analysts can use to detect related phishing infrastructure and pivot to other campaign assets during investigation.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

EvilTokens signals a shift from credential theft to token exploitation at scale. By abusing trusted authentication flows, it dissolves the traditional boundaries of phishing detection. Its PhaaS accessibility, AI enhancements, and BEC integration amplify risks for Microsoft 365-dependent organizations. Proactive threat intelligence, policy hardening, and user awareness are essential to counter this stealthy threat before it leads to significant breaches.

Identity must be continuously verified, monitored, and contextualized.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
OnyxC2 screenshot
OnyxC2
onyxc2
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
Moonrise screenshot
Moonrise
moonrise
Moonrise RAT is a newly discovered Go-based remote access trojan with zero detections at launch, featuring credential theft, keylogging, webcam access, clipboard hijacking, and UAC bypass.
Read More
FatalRAT screenshot
FatalRAT
fatalrat
FatalRAT is a malware that gives hackers remote access and control of the system and lets them steal sensitive information like login credentials and financial data. FatalRAT has been associated with cyber espionage campaigns, particularly targeting organizations in the Asia-Pacific (APAC) region.
Read More