← Back to feed
PhishingEmerging1 sourceSep 22, 2026 · 15:00via Microsoft Security Blog

Unmasking EvilTokens: Getting to the root of device code phishing

Brief

In this article

  • What is device code phishing?
  • EvilTokens platform and operations
  • EvilTokens phishing emails
  • Mitigation and protection guidance
  • Microsoft Defender XDR detections
  • Hunting queries

Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets.

This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide.

EvilTokens enabled threat actors to abuse the device code authentication flow, steal tokens, and compromise organizational accounts at scale using an AI-driven infrastructure and automating multiple parts of the attack chain.

Read more on Microsoft Security Blog