Microsoft: EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next

Microsoft: EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next

EvilTokens: A New Phishing Service Exploiting Microsoft 365 Sessions for Targeted Fraud

A sophisticated phishing-as-a-service operation, EvilTokens, is elevating credential theft by leveraging stolen Microsoft 365 sessions to conduct highly targeted financial fraud. First documented in February 2026 and sold primarily via Telegram, the service goes beyond traditional credential harvesting it analyzes compromised mailboxes to identify high-value targets, payment patterns, and business relationships, enabling attackers to craft convincing follow-up scams.

How EvilTokens Operates

Unlike conventional phishing kits, EvilTokens uses OAuth device-code phishing, tricking victims into approving access on legitimate Microsoft login pages. The attack flow begins with a lure directing users to a controlled page, where a device code is generated. Victims are then redirected to Microsoft’s real sign-in portal, where they unknowingly authorize the attacker’s session. Since the authentication occurs on Microsoft’s infrastructure, victims see no red flags only a genuine login process.

Once access is granted, EvilTokens scans the victim’s mailbox for invoices, payment requests, pending transactions, and past communications. Using AI-driven analysis, it maps organizational hierarchies, identifies key decision-makers, and mimics authentic business language to create tailored fraudulent messages. This automation allows even low-skilled attackers to execute business email compromise (BEC) attacks with precision, increasing the likelihood of success.

Scale and Impact

EvilTokens has demonstrated rapid adoption since its emergence. Over a 16-day period in 2026, the service compromised 344 organizations across five countries. Separate research uncovered over 1,000 infrastructure-related search results and 66 malicious email attachments linked to EvilTokens, indicating widespread deployment. The platform’s ability to turn stolen sessions into actionable intelligence rather than just access makes it particularly dangerous, as attackers can pivot from a single breach to multiple fraudulent transactions.

Defensive Challenges

EvilTokens exploits device-code authentication, a legitimate Microsoft feature, to bypass traditional security measures. Victims complete MFA and password authentication on real Microsoft pages, making detection difficult. The service generates fresh device codes only when a target engages with the phishing page, ensuring the 15-minute window for token theft aligns with the victim’s interaction.

Security teams are advised to restrict or disable device-code authentication where unnecessary and monitor for:

  • Unexpected device-code grants
  • Unfamiliar devices or locations
  • Unusual token issuance or consent activity
  • Large mailbox searches, new inbox rules, or unauthorized sent messages

The rise of EvilTokens underscores the need for post-compromise detection, as the real damage occurs after initial access when attackers leverage stolen sessions to orchestrate fraud. Organizations must extend monitoring beyond the phishing email to include account behavior, token reuse, and cloud data access to mitigate this evolving threat.

Source: https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/

Microsoft Security cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security

"id": "MIC1787653554",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "2/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '344 organizations (over 16 days '
                                              'in 2026)',
                        'location': ['Multiple countries (5 identified)'],
                        'type': 'Organizations'}],
 'attack_vector': 'OAuth device-code phishing, Social Engineering',
 'data_breach': {'data_exfiltration': 'Yes (used for targeted fraud)',
                 'personally_identifiable_information': 'Potentially included '
                                                        'in business '
                                                        'communications and '
                                                        'payment requests',
                 'sensitivity_of_data': 'High (business communications, '
                                        'financial data, personally '
                                        'identifiable information)',
                 'type_of_data_compromised': 'Microsoft 365 session tokens, '
                                             'Email communications, Invoices, '
                                             'Payment requests, Business '
                                             'relationships, Organizational '
                                             'hierarchies'},
 'date_detected': '2026-02-01',
 'date_publicly_disclosed': '2026-02-01',
 'description': 'A sophisticated phishing-as-a-service operation, EvilTokens, '
                'leverages stolen Microsoft 365 sessions to conduct highly '
                'targeted financial fraud. The service uses OAuth device-code '
                'phishing to trick victims into approving access on legitimate '
                'Microsoft login pages, then scans compromised mailboxes to '
                'identify high-value targets and craft convincing follow-up '
                'scams.',
 'impact': {'brand_reputation_impact': 'Potential damage due to fraudulent '
                                       'transactions and compromised business '
                                       'communications',
            'data_compromised': 'Microsoft 365 session tokens, Email '
                                'communications, Invoices, Payment requests, '
                                'Organizational hierarchies, Business '
                                'relationships',
            'identity_theft_risk': 'High (stolen session tokens and business '
                                   'communications)',
            'operational_impact': 'Unauthorized access to business '
                                  'communications, Fraudulent transactions, '
                                  'Compromised business relationships',
            'payment_information_risk': 'High (fraudulent payment requests and '
                                        'invoices)',
            'systems_affected': 'Microsoft 365 mailboxes, Authentication '
                                'systems'},
 'initial_access_broker': {'entry_point': 'OAuth device-code phishing',
                           'high_value_targets': 'Key decision-makers, '
                                                 'Business relationships, '
                                                 'Payment patterns'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The incident highlights the need for post-compromise '
                    'detection, as attackers leverage stolen sessions for '
                    'fraud after initial access. Organizations must monitor '
                    'account behavior, token reuse, and cloud data access '
                    'beyond the initial phishing email.',
 'motivation': 'Financial fraud, Credential theft',
 'post_incident_analysis': {'corrective_actions': 'Restrict device-code '
                                                  'authentication, Implement '
                                                  'enhanced monitoring for '
                                                  'account behavior and token '
                                                  'reuse',
                            'root_causes': 'Exploitation of legitimate '
                                           'Microsoft 365 device-code '
                                           'authentication feature, Lack of '
                                           'post-compromise detection'},
 'recommendations': ['Restrict or disable device-code authentication where '
                     'unnecessary',
                     'Monitor for unexpected device-code grants, unfamiliar '
                     'devices or locations, and unusual token issuance or '
                     'consent activity',
                     'Implement enhanced monitoring for large mailbox '
                     'searches, new inbox rules, and unauthorized sent '
                     'messages',
                     'Extend monitoring to include account behavior, token '
                     'reuse, and cloud data access'],
 'references': [{'source': 'Cybersecurity Research'}],
 'response': {'containment_measures': 'Restrict or disable device-code '
                                      'authentication, Monitor for unexpected '
                                      'device-code grants, Unfamiliar devices '
                                      'or locations, Unusual token issuance or '
                                      'consent activity',
              'enhanced_monitoring': 'Monitor for large mailbox searches, new '
                                     'inbox rules, unauthorized sent messages',
              'remediation_measures': 'Post-compromise detection, Enhanced '
                                      'monitoring of account behavior, token '
                                      'reuse, and cloud data access'},
 'threat_actor': 'EvilTokens (Phishing-as-a-Service operators)',
 'title': 'EvilTokens: A New Phishing Service Exploiting Microsoft 365 '
          'Sessions for Targeted Fraud',
 'type': 'Phishing-as-a-Service, Business Email Compromise (BEC)',
 'vulnerability_exploited': 'Legitimate Microsoft 365 device-code '
                            'authentication feature'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.