Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

EvilTokens

2
Global rank
2
Month rank
2
Week rank
0
IOCs

EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.

Phishingkit
Type
Unknown
Origin
Unknown
First seen
15 September, 2026
Last seen

How to analyze EvilTokens with ANY.RUN

Type
Unknown
Origin
Unknown
First seen
15 September, 2026
Last seen

IOCs

IP addresses
2.23.246.9
172.64.146.244
151.101.66.133
34.160.81.0
104.18.23.222
150.171.28.11
74.179.77.164
142.251.14.101
172.67.203.197
40.126.31.73
150.171.109.106
74.125.250.129
20.190.160.3
135.232.92.137
184.86.251.11
48.209.133.15
23.216.77.21
104.18.94.41
23.11.41.157
172.64.147.119
Hashes
fac0a85e4f5907c8036b0052214b777ddbacea9420e5903526272dc76bd4c7b6
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
84acd485899333cbdf5ad1f68d8c31658d5ecc9ee8dddf62098a2218687d7e77
d013cf4212cff86f9af45c51cdb8b9efa5a494005420e100aec8f9e9b9a290e4
266da3069a00ae9193ac11ae63771f5aeefa18b1862a441e03d319fde7bc1680
8b5922daab79d70297f90db7815097ce3dc92e1ada82b56c5206d3ea4554110b
d0e0c6db51b94fe5424ddbe62fee2ca12616fed7f9fae9ed4ccf121ef74de3a3
5a0674757b36cd1a603934e814ca42fb1a9c3c2a7fb8cf9ffe5dc1f7337badcb
0516a11223c7dc4ed434e8c6dae89ac7bad80f006a5094502522cd38b4f53cb6
8dd1b999d16eccef41a05237186710bff4609d9b676389226e2ea8e339914d9d
b58b77da7d6b8189a959a9003a2f3b2adef58b01d8bb1251c1361d843f3a1e6b
cdb4ee2aea69cc6a83331bbe96dc2caa9a299d21329efb0336fc02a82e1839a8
4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945
6e340b9cffb37a989ca544e6bb780a2c78901d3fb33738768511a30617afa01d
7f04991cb2d08512ee29d864bc64cdad078ebc2af93cca9005b194e5b64e747b
398a39a13f878ad0b5ec716ebc51fb98f77e62e1ad19c5991b8ea1c0d338eb20
343662e18a82a92087923631213e4e048e03e7a3d527d313a64a2fb763371000
7c3c252f2f62be26050dce907c35ab1f78121e34f34e672840da5d00980479ba
7ac0012bd562052affc83ecea201e7d46aa9ead1a4f62325226f78fe38056763
5226756576b4a47de18921ee1009e4f4e0452de3ca21438664eb31900be3ef9f
Domains
fe3cr.delivery.mp.microsoft.com
stun1.l.google.com
ocsp.digicert.com
static.kmail-lists.com
edge.microsoft.com
go.microsoft.com
copilot.microsoft.com
manage.kmail-lists.com
activation-v2.sls.microsoft.com
edge-consumer-static.azureedge.net
login.live.com
fonts.googleapis.com
crl.microsoft.com
challenges.cloudflare.com
xpaywalletcdn.azureedge.net
a.klaviyo.com
google.com
www.bing.com
slscr.update.microsoft.com
login.microsoftonline.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:bqbroczdskx0uujsgtcxjgrmuo8fvl2sevzqpgq7aua&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://manage.kmail-lists.com/subscriptions/subscribed?a=wvej6k&g=tpemtb
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://manage.kmail-lists.com/csp/
https://manage.kmail-lists.com/consent-pages/client/subscribe-success-pages?a=wvej6k&g=tpemtb
https://manage.kmail-lists.com/media/favicon-16by16.png
https://static.kmail-lists.com/onsite-consent-pages/js/onsiteconsentpages.js
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://edge.microsoft.com/autofillservice/core/page/9001016338255921368/3917846799112216986?cidalgoversion=2
https://o19233.ingest.sentry.io/api/4509158594838529/envelope/?sentry_key=d11ccded41fc6494e3e543c42786afbe&sentry_version=7&sentry_client=sentry.javascript.react%2f7.116.0
https://fast.a.klaviyo.com/custom-fonts/api/v1/company-fonts/onsite?company_id=wvej6k
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://fonts.googleapis.com/css2?family=anton:ital,wght@0,400&family=antonio:ital,wght@0,100;0,400;0,500;0,700&display=swap
https://a.klaviyo.com/media/js/lib/iframeresizer.contentwindow.js
Last Seen at

Recent blog posts

post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 438
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5189
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 10301
comments 0

EvilTokens: How AI-Powered Device Code Phishing Is Making Business Email Compromise Unstoppable

Key Takeaways

  1. EvilTokens bypasses MFA by abusing Microsoft's own device code OAuth flow, obtaining valid tokens without password theft.

  2. As a PhaaS kit sold on Telegram, it democratizes sophisticated attacks, enabling rapid scaling with minimal technical skill.

  3. AI-powered features generate convincing lures and automate BEC, increasing both volume and success rates.

  4. Persistent refresh tokens allow long-term access, device registration, and silent authentication across M365 services.

  5. Organizations in finance, government, healthcare, and other M365-heavy sectors are prime targets globally.

  6. Security teams can query ANY.RUN's Threat Intelligence Lookup for known EvilTokens domains, URLs, and infrastructure indicators in real time — enriching SIEM alerts, hunting for campaign IOCs, and staying ahead of the platform's rapid infrastructure rotation before damage is done.

destinationIP:"75.98.162.49".

Malicious IP linked to EvilTokens Malicious IP linked to EvilTokens

  1. ANY.RUN's Interactive Sandbox lets analysts safely detonate EvilTokens lures. Submit suspicious PDFs, HTML documents, and phishing URLs from EvilTokens campaigns to observe behavior, capture network IOCs, and generate detection signatures.

View analysis session

Eviltokens phishing analysis in Interactive Sandbox EvilTokens phishing analysis in Interactive Sandbox

What is EvilTokens Malware?

EvilTokens is a turnkey, productized PhaaS platform sold to criminal affiliates via Telegram. Unlike conventional phishing kits that replicate Microsoft login pages or intercept credentials in transit, EvilTokens abuses the legitimate OAuth 2.0 Device Authorization Grant (a Microsoft authentication flow designed for devices with limited input capabilities, such as smart TVs, IoT sensors, and printers) to steal valid OAuth tokens after the victim has completed a fully legitimate MFA challenge on Microsoft's real infrastructure.

First identified by Sekoia's Threat Detection & Research (TDR) team in early March 2026, EvilTokens had already been circulating in underground cybercrime communities since mid-February 2026. Its operator, known as eviltokensadmin, advertised the kit in private Telegram channels frequented by threat actors specializing in Adversary-in-the-Middle (AitM) phishing and BEC fraud.

What sets EvilTokens apart from the crowded phishing kit marketplace is its comprehensive, full-lifecycle attack package. Beyond the core phishing module, the platform provides affiliates with:

  • Ready-made phishing page templates impersonating services like Adobe Acrobat, DocuSign, SharePoint, OneDrive, and Microsoft itself.

  • Token weaponization tools to immediately leverage stolen OAuth credentials.

  • Email harvesting and inbox analysis powered by AI, using Meta's LLaMA model to automatically prioritize high-value conversations.

  • A built-in webmail client, internally branded "MailVault," styled to mimic Outlook, enabling attackers to read, compose, and send emails directly from compromised inboxes.

  • Reconnaissance via the Microsoft Graph API, including automatic detection of Exchange and Global Administrator accounts (flagged with a crown icon) to enable privilege escalation.

  • Keyword alerting via Telegram, so attackers are instantly notified when terms like "invoice," "wire transfer," or "payment" appear in harvested mailboxes.

  • AI-generated phishing lures, with LLMs crafting personalized and contextually convincing social engineering messages at scale.

  • Multi-tenant SaaS architecture, giving each affiliate their own isolated environment, unique credentials, and a pool of compromised accounts

The platform operates through fully featured Telegram bots and a Vue.js admin panel marketed externally as "MailVault — Enterprise Email Management Platform" to disguise its true nature. It is under continuous development, with the operator publicly announcing plans to expand support to Gmail and Okta phishing in the near future.

Researchers at Abnormal AI assessed with high confidence that EvilTokens' underlying code was likely AI-generated, reflecting a broader and alarming trend of AI accelerating both the development and operation of criminal phishing infrastructure.

How EvilTokens Threatens Businesses and Organizations

EvilTokens targets the identity layer — the very fabric of modern enterprise security —without triggering typical credential-based alerts.

Key risks include:

  • MFA Bypass: Instead of stealing passwords, attackers obtain valid tokens, effectively sidestepping MFA protections.

  • Persistent Access: Refresh tokens allow long-term access even after password resets.

  • Business Email Compromise (BEC): Attackers gain control of corporate email, enabling fraud, invoice manipulation, and executive impersonation.

  • Data Exfiltration: Access extends to email, cloud storage, Teams, and SSO-connected apps.

  • Stealth and Evasion: Because authentication occurs through legitimate Microsoft pages, detection becomes significantly harder.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Which Industries Are Most at Risk?

EvilTokens is opportunistic, but not random. It gravitates toward roles with access and authority.

Most targeted sectors:

  • Finance & Banking (payment authorization, fraud potential);

  • Healthcare (sensitive data + weaker identity controls);

  • Government & Public Sector (high-value intelligence);

  • Technology & SaaS companies (cloud-heavy environments);

  • Logistics & Supply Chain (invoice and partner fraud vectors).

High-risk roles include:

  • CFOs and finance teams

  • HR and payroll staff

  • Executives and decision-makers

Campaigns have already impacted hundreds of organizations globally across industries. The most impacted countries as of late March 2026 include the United States, Australia, Canada, France, India, Switzerland, and the United Arab Emirates — essentially any country with a significant concentration of Microsoft 365 enterprise users and active cross-border financial flows.

EvilTokens’ Malware Infection Vector and Spread

EvilTokens' delivery chain is engineered for maximum deception at every stage.

Stage 1 — Initial lure delivery. Phishing emails are sent from previously compromised legitimate accounts — real Microsoft 365 or Google Workspace mailboxes belonging to other victims. This means the sender passes all standard email authentication checks: SPF PASS, DKIM PASS, and DMARC PASS. The lure emails impersonate routine business communications: shared document notifications from OneDrive or SharePoint, DocuSign signing requests, invoice approvals, calendar invites, or HR announcements.

Attachments may be PDF, HTML, DOCX, XLSX, or SVG files containing either a QR code or a hyperlink leading to the phishing infrastructure.

Stage 2 — Bot filter gate. Links in lure emails point not to EvilTokens infrastructure directly but to compromised legitimate websites where a PHP bot filter validates whether the visitor is a real browser executing JavaScript. Automated sandbox crawlers and security scanners that lack JavaScript are trapped in a meta refresh loop and never reach the payload, providing a layer of detection evasion.

Stage 3 — Identity verification gate page. Legitimate visitors are redirected to a gate page (versioned, branded "Identity Verification") that collects the target's email address and passes it to a Cloudflare Worker, further obscuring the backend infrastructure.

Stage 4 — Phishing page. The victim is presented with a page impersonating a trusted service (Adobe Acrobat, DocuSign, Microsoft). The page displays a legitimate Microsoft device code generated in real time by EvilTokens' C2 server calling Microsoft's /devicecode endpoint alongside instructions to "verify identity" by visiting Microsoft's real device login page and entering the displayed code.

Stage 5 — Token harvest. When the victim authenticates on Microsoft's genuine login page (completing real MFA in the process), EvilTokens' C2 simultaneously polls Microsoft's /token endpoint to collect the resulting OAuth access token and refresh token. The attacker now controls the session.

Stage 6 — Lateral spread. With access to the victim's mailbox and contacts, attackers identify further high-value targets within the organization and among its business partners, launching new lure campaigns from the now-compromised legitimate account, perpetuating the cycle.

How Does EvilTokens Function?

Once tokens are harvested, EvilTokens provides a full post-compromise operational suite delivered through the MailVault admin panel.

Token weaponization. The short-lived access token (valid 60–90 minutes) is used immediately to extract emails from Exchange Online, documents from SharePoint and OneDrive, and conversation history from Microsoft Teams. The refresh token (valid 90 days, rolling) is used to silently obtain new access tokens, maintaining persistent access to the account without re-authentication.

Privilege escalation detection. JWT claim parsing within the MailVault panel automatically identifies whether the compromised account holds Exchange Administrator or Global Administrator roles flagging these high-privilege accounts so affiliates know to prioritize them for deeper exploitation.

AI-powered email analysis. Using Meta's LLaMA model integrated into the platform, EvilTokens automatically analyzes harvested emails to surface high-value threads: financial conversations, invoice chains, payment instructions, and sensitive business discussions.

Keyword alerting. A Telegram-integrated keyword scanner notifies affiliates in real time when target terms appear in harvested mailboxes, enabling rapid exploitation of time-sensitive financial transactions.

BEC operations via MailVault. The built-in webmail client allows attackers to read all emails in a compromised inbox, download attachments, and compose and send messages that genuinely originate from the victim's account. Attackers can insert themselves into ongoing financial threads, redirect payments, impersonate executives, or exfiltrate sensitive documents without any technical complexity.

Persistence and device registration. Refresh tokens can be used to register an attacker-controlled device in Entra ID, granting even more durable access that persists beyond password resets unless explicitly revoked at the device level.

AI-generated lures. LLMs integrated into the platform generate contextually tailored phishing messages for new targets, varying content across recipients to evade signature-based detection and reduce campaign fatigue.

How Can Businesses Proactively Protect Against EvilTokens Malware?

Defending against a threat as technically sophisticated and rapidly evolving as EvilTokens requires moving from reactive incident response to proactive, intelligence-driven security.

ANY.RUN's Threat Intelligence Lookup gives security teams direct, real-time access to threat data collected from millions of malware analysis sessions in ANY.RUN's Interactive Sandbox. For EvilTokens specifically, TI Lookup enables organizations to:

  • Query known EvilTokens indicators of compromise and instantly determine whether any of these indicators have appeared in their environment or email logs.
  • Track infrastructure evolution in real time. TI Lookup surfaces newly observed indicators as they are processed, enabling defenders to stay ahead of infrastructure changes rather than chasing yesterday's IOCs.

threatName:"eviltokens".

Fresh EvilTokens IOCs Fresh EvilTokens IOCs found in TI Lookup

  • Hunt for EvilTokens-linked network artifacts — such as requests to Microsoft's /devicecode and /token endpoints combined with suspicious referral chains — that may indicate active campaigns targeting the organization.
  • Contextualize alerts. When a SIEM or EDR fires on a suspicious domain or URL, TI Lookup provides immediate context: is this known EvilTokens infrastructure? What campaigns is it linked to? What was observed in sandbox analysis?

You can start from looking up the threat by name to get a selection of recent sandbox analysis sessions featuring EvilTokens attacks and pivot your research and hunting from there:

threatName:"eviltokens".

EvilTokens sandbox analyses EvilTokens sandbox analyses found via TI Lookup

Additional Measures:

  • Enforcing Conditional Access policies to restrict or monitor device code flows.

  • User education on unusual "enter code on Microsoft login" requests.

  • Monitoring for anomalous token usage or new device registrations in Entra ID.

  • Advanced email filtering for AI-generated lures and attachment-based phishing.

  • Implementing least-privilege access and regular token reviews.

  • Behavioral analytics to detect post-compromise activity like unusual Graph API calls.

Sandbox Analysis of EvilTokens Sample

See the detonation of an EvilTokens sample

EvilTokens attack chain in the sandbox EvilTokens attack chain in the sandbox

The attack often begins with a landing page impersonating DocuSign, prompting the user to “Review Document.” The victim is shown a verification code and instructed to copy it.

Key red flag: this is not a real DocuSign signing workflow. It is a scripted sequence:

  • Copy the verification code,

  • Click “Continue to Microsoft”,

  • Paste the code into Microsoft’s device login page.

The address bar typically shows a *.workers.dev domain instead of a legitimate DocuSign domain.

A Microsoft window then opens at login.microsoftonline.com/…/deviceauth, showing the form “Enter code to allow access.” The user enters the same code they were shown on the fake page. This action takes place on a legitimate Microsoft domain, even displaying Microsoft’s own warning: “Do not enter codes from sources you don’t trust.”

Fake verification granting access to external client Fake verification granting access to external client

The following screen states: “You’re signing in to Microsoft Office on another device…” From the victim’s perspective, the process still appears legitimate. In reality, they are approving access for an external client controlled by the attacker, not verifying the document they originally clicked.

The key point is: the user never enters their password on a fake site. Instead, they are guided through legitimate Microsoft infrastructure and manually transfer a code.

How Automatic SSL Decryption Ensures Instant Detection

From an investigation standpoint, these phishing pages often rely on JavaScript loaders and encrypted HTTPS traffic to hide the real workflow from traditional scanners.

This is where SSL decryption in the ANY.RUN Sandbox becomes critical. By extracting TLS encryption keys directly from process memory and decrypting HTTPS traffic during execution, the sandbox reveals the hidden scripts, API requests, and attacker infrastructure involved in the phishing flow.

SSL decryption allows Suricata IDS rules to detect malicious encrypted traffic SSL decryption allows Suricata IDS rules to detect malicious encrypted traffic

In this case, SSL decryption exposed the malicious JavaScript responsible for orchestrating the device authorization process and revealed high-confidence network indicators used by the phishing kit. Among them were specific API requests such as /api/device/start and /api/device/status/, along with a distinctive X-Antibot-Token header used in communication with the backend.

Traffic decrypted with SSL decryption

Traffic decrypted with SSL decryption Traffic decrypted with SSL decryption

When these artifacts appear in HTTP requests to non-legitimate hosts, they become high-signal network IOCs that analysts can use to detect related phishing infrastructure and pivot to other campaign assets during investigation.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

EvilTokens signals a shift from credential theft to token exploitation at scale. By abusing trusted authentication flows, it dissolves the traditional boundaries of phishing detection. Its PhaaS accessibility, AI enhancements, and BEC integration amplify risks for Microsoft 365-dependent organizations. Proactive threat intelligence, policy hardening, and user awareness are essential to counter this stealthy threat before it leads to significant breaches.

Identity must be continuously verified, monitored, and contextualized.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Sality screenshot
Sality
sality
Sality is a highly sophisticated malware known for infecting executable files and rapidly spreading across networks. It primarily creates a peer-to-peer botnet that is used for malicious activities such as spamming, data theft, and downloading additional malware. Sality has strong persistence mechanisms, including disabling security software, making it difficult to remove. Its ability to spread quickly and silently, along with its polymorphic nature, allows it to evade detection by traditional antivirus solutions.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
EvilProxy screenshot
EvilProxy
evilproxy
EvilProxy is a phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) and hijack user sessions. It leverages reverse proxy techniques to harvest credentials and session cookies, posing a serious threat to both individuals and enterprises.
Read More
Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More
XRed screenshot
XRed
xred
XRed operates as a stealthy backdoor, enabling cybercriminals to gain unauthorized remote access to infected systems. XRed has gained particular notoriety for its distribution through trojanized legitimate software and hardware drivers, making it exceptionally dangerous due to its ability to masquerade as trusted applications.
Read More
Orcus RAT screenshot
Orcus RAT
orcus rat trojan
Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.
Read More