CyberSecurity SEE

EvilTokens Exploits Microsoft Device Codes to Hijack Accounts Without Password Theft

EvilTokens Exploits Microsoft Device Codes to Hijack Accounts Without Password Theft

EvilTokens, a new criminal operation, is advancing phishing-as-a-service (PhaaS) by leveraging Microsoft’s device authorization flow to acquire valid Microsoft 365 tokens. This novel approach enables attackers to exploit legitimate sign-in procedures to gain unauthorized access to user accounts without necessarily stealing credentials.

Victims engaging with this scheme might find themselves unknowingly participating in an authorized session controlled by the attacker. Despite successfully navigating a genuine Microsoft sign-in and multi-factor authentication (MFA) challenge, the victims inadvertently approve access for malicious actors. This manipulation marks a significant evolution in the phishing landscape, where user interaction is cleverly orchestrated to achieve the attacker’s goals.

The operation, which gained visibility in Telegram channels starting in mid-February 2026, has drawn attention from cybersecurity researchers, particularly those at Sekoia. They identified EvilTokens as a “turnkey” phishing kit, specifically tailored for Microsoft’s device-code authentication. The platform’s business model is equally concerning; it boasts a $1,500 fee for panel access and a $500 monthly charge for active infrastructure and backend API access. This financial structure indicates a commodification of phishing capabilities, enticing a broader range of cybercriminals to participate.

EvilTokens distinguishes itself from traditional credential phishing by eliminating the need for a cloned Microsoft login page or the theft of passwords. Instead, it exploits the OAuth 2.0 Device Authorization Grant—a legitimate system designed for devices that struggle with browser-based authentication. The intended flow involves a user authenticating on one device while entering a code associated with another device, thus creating a separation that EvilTokens manipulates for its benefit.

In a typical scenario, a victim receives an enticing bait that leads them to an attacker-controlled page capable of generating a valid Microsoft device code. The fraudulent interface instructs the victim to proceed to Microsoft’s genuine device-login portal, where they enter the code and authenticate normally, including the MFA challenge. Consequently, Microsoft issues both access and refresh tokens linked to the session initiated by the attacker, solely because the victim inadvertently approved the request.

The core issue lies in the distinction that while MFA remains technically intact, the victim has been manipulated into authorizing a legitimate authentication. This enables attackers to obtain usable tokens that grant access to Microsoft 365 services while filtering out the conspicuous indicators typically associated with compromised credential theft.

Sekoia noted that EvilTokens pages have been circulating since mid-February, with the platform gaining traction in phishing-focused criminal communities by early March. This advancement addresses a significant limitation in conventional device-code phishing: the short lifespan of Microsoft device codes, usually valid for only 15 minutes. Rather than generating a code at the time a phishing message is transmitted, EvilTokens creates a code after the target engages with the lure page, increasing the likelihood that the authorization request remains valid when the victim reaches the legitimate Microsoft login page.

What makes EvilTokens particularly alarming is its “post-compromise” capabilities. Unlike traditional PhaaS services that primarily focus on phishing infrastructure—like lures, landing pages, and credential gathering—EvilTokens extends its offerings to include account reconnaissance and preparation for business email compromise (BEC). As reported by Flare researchers, the platform has integrated AI-driven features designed to assist affiliates in analyzing compromised Microsoft 365 environments. These functionalities aim to pinpoint invoices, payment requests, transaction discussions, decision-makers, and approval workflows, which can be exploited for targeted fraud.

Cisco Talos examined an affiliate panel dubbed ARToken, which shared infrastructure and operational patterns with EvilTokens. They discovered that this panel offered over 80 API endpoints supporting device-code phishing, persistent tokens, email access, SharePoint exfiltration, and workflows tailored for BEC. This observation pinpointed an ecosystem of maturing cybercrime rather than a solitary phishing kit.

The operational reach of EvilTokens is already extensive. Huntress tracked a 16-day campaign that targeted 344 organizations across the United States, Canada, Australia, New Zealand, and Germany. They observed that the incident, which commenced with initial cases in February, gained momentum in March, attributing 87.4% of the cases to indicators of EvilTokens’ device-code phishing techniques.

In view of these developments, cybersecurity defenders are encouraged to restrict device-code authentication wherever it’s not essential and to implement Conditional Access policies tailored to approved users, applications, devices, and locations. Security teams should remain vigilant regarding unusual device-code grants, irregular token issuance, and atypical sign-in sources. Moreover, mailbox-rule changes, suspicious consent activity, and unexpected access to cloud resources should trigger alerts.

Most crucially, user awareness training must adapt to this evolving threat. A genuine Microsoft login page or a successful MFA challenge no longer guarantees the safety of a request. Users should treat unsolicited device codes and authentication prompts originating from emails, chat messages, or unexpected notifications as potential phishing attempts, fostering a culture of cautious engagement in digital interactions.

Source link

Exit mobile version