A new phishing tool known as EvilTokens is being used to hack Microsoft 365 accounts. This PhaaS (phishing-as-a-service) kit exploits the OAuth 2.0 device authorization grant flow. Instead of creating fake login pages to steal credentials, EvilTokens weaponizes a legitimate authentication process, representing a significant evolution in account theft tactics.
Understand how EvilTokens manipulates the authentication system
ESET researchers have detailed the operating mechanism of this attack. Attackers send victims bait that poses as invoices, shared documents, calendar invites, or SharePoint access requests.
When interacting with these malicious links, the victim is directed to a page that requests a Microsoft device code, valid for just 15 minutes.
A diagram illustrating this protocol, released by Microsoft and replicated by Sekoia, helps to visualize the complexity of the approach.
The crucial point is that this code belongs to the attacker’s session. Thus, the victim unknowingly grants authorization to the attacker’s device, not their own, allowing Microsoft to release access and update tokens for the criminal session.
Sample phishing templates used by EvilTokens have been documented by Sekoia, showing the variety of visual approaches employed.
Full coverage: Latest News (EN)
Once access is gained, criminals are able to manipulate and access a range of Microsoft 365 resources, including corporate email, files, Teams, SharePoint and OneDrive. This even allows them to plan business email compromise (BEC) attacks. This phishing kit has been disseminated through Telegram channels and its activity has been detected in active attacks since at least February 2026.
The high risks of the new cyber attack technique
Originally, the OAuth device code flow was designed for equipment such as smart TVs or printers. These devices require a short code to be authenticated on a Microsoft page, using another device, which culminates in the issuance of access tokens for the initial equipment.
As reported by ESET, attackers have the ability to generate the code and trick the victim into entering it, while Microsoft perceives the process as a valid authentication flow. This particularity makes EvilTokens especially dangerous, as traditional security defenses focused on identifying fraudulent login pages can fail, requiring closer surveillance of the authentication flows themselves.
Cybersecurity researchers have previously documented this kit, with Sekoia indicating its use in a campaign that reached more than 340 organizations across multiple countries in March 2026. Additionally, Microsoft described an artificial intelligence-driven campaign that employed dynamic device code generation to increase the success rate of EvilTokens attacks.
Follow: all about 2FA Bypass
A crucial point is that the attack can bypass two-factor authentication (2FA). This occurs not through technical exploits, but rather by tricking the victim into finalizing the 2FA process for the attacker’s own session.
Security measures and recommendations to protect against PhaaS
Microsoft advises implementing Conditional Access policies to block the flow of device code in environments where it is not essential.
It’s critical that users and administrators be aware of unusual device code authentications, unknown devices, risky login attempts, suspicious token usage, and the creation of new inbox rules.
In early June, Arctic Wolf Labs monitored a PhaaS operation called Kali365, first identified in April 2026, that began targeting platforms including Microsoft, Okta, DocuShare, AWS, and MAX Messenger.
In January, Okta SSO accounts were targeted by an alleged phishing campaign from the ShinyHunters group, which used custom PhaaS kits for its attacks.

