EVILTOKENS

EVILTOKENSEvilTokens

Description

Phishing-as-a-service (PhaaS) kit abusing the OAuth 2.0 device authorization grant (device code phishing) against Microsoft 365: the operator initiates the device code flow and lures the victim into approving it on Microsoft's legitimate sign-in page, obtaining access and refresh tokens without capturing the password. Active since February 2026, first publicly reported in March 2026 by Huntress and Sekoia. Microsoft attributes its development and support to Storm-2992, which sold it to affiliates on Telegram; post-compromise features include AI-assisted mailbox triage and lure generation and Microsoft Graph reconnaissance, feeding business email compromise. Infrastructure disrupted by Microsoft's Digital Crimes Unit with partners in September 2026.
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.