search

LEMON BLOG

EvilTokens Phishing Kit Abuses Microsoft Device Code Sign-In to Target Business Email Accounts

A newly documented phishing campaign is taking advantage of a legitimate Microsoft authentication process to compromise corporate email accounts without ever needing to steal a victim's password. The phishing kit, known as EvilTokens, has been active since February 2026 and has been linked to business email compromise campaigns targeting more than 12,000 inboxes across over 10,000 organisations worldwide.

What makes the campaign particularly dangerous is the way it abuses Microsoft's device code authentication flow. Instead of asking the victim to enter a password into an obviously suspicious login page, the phishing process convinces the user to approve an attacker-controlled login through Microsoft's own legitimate sign-in process. Once that approval happens, the attacker receives valid access tokens that can be used to enter the victim's mailbox.

No Password Theft Is Required

Traditional phishing attacks often depend on tricking a user into entering their username and password into a fake login page. EvilTokens takes a different approach. The attacker starts a device-code authentication session and then sends the victim a lure asking them to enter or approve a code through the legitimate Microsoft sign-in portal.

The victim may complete normal authentication steps, including password and multifactor authentication, without realising that the session they are approving actually belongs to the attacker. Once the process is completed, the attacker's waiting session receives the access tokens. The phishing site never needs to directly capture the victim's password.

This makes the attack particularly deceptive because the user may see a genuine Microsoft authentication screen and assume that the request is safe. The warning sign is not necessarily the website itself, but whether the user initiated the device-code request in the first place.

The Lures Look Like Ordinary Business Messages

EvilTokens campaigns typically begin with urgent-looking emails designed to create pressure and familiarity. Common themes include invoices, shared files, document signatures and expiring passwords. The message may contain a malicious URL, PDF attachment or HTML file that eventually directs the victim toward the device-code sign-in process.

The campaign infrastructure has reportedly used 44 different phishing themes, helping attackers vary their messages and potentially avoid simple content-based detection. Requests for proposals, invoices and shared documents are among the examples identified.

That variety is important because business email compromise often succeeds by blending into normal corporate communication. A request to review a document or approve an invoice may not look unusual to someone who receives dozens of similar emails every day.

Stolen Tokens Give Attackers Mailbox Access

Once EvilTokens obtains valid access tokens, attackers can use them to access the victim's email, search messages and extract information that may help with fraud. The tokens can also support persistence inside the account rather than giving the attacker only short-lived access.

One technique involves creating malicious inbox rules that hide or redirect communications. For example, an attacker could automatically move replies from a finance department into a hidden folder so the legitimate account owner does not immediately notice suspicious conversations.

In some cases, stolen tokens may also be used to register additional devices for mailbox access, creating another way for the attacker to maintain control. This can make the compromise more difficult to contain if responders only reset the password without checking sessions, devices and mail rules.

AI Is Used to Scale the Attack

EvilTokens also incorporates AI capabilities to make the phishing operation more efficient. After gaining mailbox access, threat actors can use AI assistants to examine the victim's email activity and generate phishing messages based on the information already available inside the account.

That can make follow-up attacks considerably more convincing. Instead of sending generic messages, attackers can reference real conversations, business relationships, invoice patterns or ongoing projects discovered in the compromised mailbox.

The toolkit can also use Microsoft Graph reconnaissance to map organisational structures and permissions. As long as the stolen tokens remain valid, this may help the attacker identify additional targets or opportunities for lateral movement.

Business Email Compromise Is the Main Objective

The purpose of the attack is not necessarily to deploy malware on the victim's computer. Instead, EvilTokens is designed to compromise organisational email accounts and use those accounts for Business Email Compromise, or BEC.

Once inside a mailbox, attackers can search for payment information, upcoming transactions and conversations involving suppliers or executives. They can then impersonate the legitimate user when contacting colleagues, customers or external partners.

This makes BEC particularly dangerous because the fraudulent message may originate from a real corporate account rather than an obviously spoofed address. To the recipient, the email can look completely legitimate because it is being sent through the compromised mailbox itself.

The risk becomes even greater when attackers have already studied earlier conversations and can mimic the tone, context and timing of genuine business communications.

The Campaign Has Reached Multiple Industries

EvilTokens activity has been observed across several sectors, including wholesale distribution, construction, financial services, real estate, higher education and healthcare.

The highest concentrations of observed victim activity were reported in the United States, Canada, the United Kingdom, Australia, India and France.

This spread suggests the campaign is not targeting one specific type of organisation. Any business that relies heavily on Microsoft cloud email and device-code authentication could potentially become a target if the relevant security controls are not in place.

Multifactor Authentication Alone May Not Stop This

One of the most important lessons from EvilTokens is that MFA does not automatically prevent every account takeover. In this scenario, the victim may successfully complete MFA themselves while unknowingly authorising the attacker's login session.

The problem is therefore not that the attacker bypasses MFA in the conventional sense. Instead, the attacker tricks the legitimate user into approving access.

This is why user awareness remains important even in organisations with strong authentication controls. Staff need to understand that they should never approve a device code or sign-in request they did not initiate themselves.

Blocking Device Code Sign-In Can Reduce the Risk

Microsoft recommends that organisations block device code sign-in where it is not required and limit exceptions to situations where the functionality is genuinely necessary.

This is one of the strongest preventative measures because it removes the authentication flow that EvilTokens is abusing. If an organisation does not use device-code authentication for legitimate business purposes, leaving it enabled creates unnecessary attack surface.

Where device code authentication is required, access should be narrowly scoped and monitored closely.

Employees Should Be Trained Not to Approve Unexpected Codes

Security awareness training should also include a very simple rule: never approve or enter a device code that you did not personally request. Microsoft specifically recommends educating employees about this behaviour while monitoring for unusual sign-ins and unexpected inbox rules.

Payment requests should also be independently verified, particularly when bank account details or payment instructions suddenly change. A phone call to a known contact or another trusted communication channel can often expose BEC attempts before money is transferred.

The stronger the financial impact of the request, the less organisations should rely on email alone to verify it.

Compromised Accounts Need More Than a Password Reset

If an EvilTokens compromise is suspected, responders should revoke refresh tokens and review mailbox activity rather than relying solely on a password change.

The advisory also warns that existing access tokens may remain usable for up to an hour after normal session revocation. In situations where immediate containment is required, temporarily disabling the compromised account may be necessary while responders investigate registered devices, active sessions and hidden inbox rules.

This is a critical point because token-based attacks can survive actions that would normally be expected to stop a credential compromise. Resetting the password is important, but it may not immediately invalidate every token or persistent session already issued.

The Attack Chain Leaves Several Detection Opportunities

The advisory maps EvilTokens activity across several stages of an intrusion. These include device-code authentication for initial access, token theft, malicious device registration, unusual Microsoft Graph activity and malicious inbox rules.

For defenders, this means there are multiple opportunities to detect suspicious activity even if the original phishing email is missed.

Unusual device-code authentication, new registered devices, sudden increases in Graph API requests and unexpected inbox-rule creation should all be investigated when they occur outside normal user behaviour.

The more telemetry an organisation retains across identity, Microsoft 365 and mailbox activity, the easier it becomes to identify the attack before it turns into financial fraud.

Final Thoughts

EvilTokens demonstrates how phishing continues to evolve beyond simply stealing usernames and passwords. By abusing Microsoft's legitimate device-code authentication process, attackers can convince victims to authorise access themselves and obtain valid tokens without ever seeing the account password.

The use of AI makes the threat even more concerning because compromised mailbox content can be analysed and turned into increasingly convincing follow-up messages. Combined with Microsoft Graph reconnaissance, malicious inbox rules and additional device registration, the attackers can turn one successful authentication into a much broader business email compromise operation.

For organisations, the most effective response is layered: restrict device-code authentication where possible, educate users not to approve unexpected codes, monitor abnormal sign-ins and mailbox rules, verify financial requests independently and revoke tokens aggressively when compromise is suspected.

The biggest lesson is simple: a familiar Microsoft login screen does not automatically mean the login request itself is legitimate.

If you did not initiate the authentication, do not approve it.

Logitech Yeti 2 Brings Voice Proximity Tracking, A...
How Visual Surprise Makes Advertising More Memorab...

Related Posts

 

Comments 0

Loading latest comments...
Friday, 25 September 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection