EvilTokens (Mar 2026): Device Code Phishing-as-a-Service Hits Microsoft 365
Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code phishing, according to research from the Cloud Security Alliance and reporting by The Hacker News and others.
What was reported
- EvilTokens launched as a phishing-as-a-service offering in February 2026, packaging a technique previously associated with state-sponsored actors.
- Within weeks, campaigns using it compromised more than 340 organizations across five countries, according to research published in March.
- Microsoft observed 10 to 15 distinct device code phishing campaigns launching every 24 hours from mid-March 2026, with hundreds of organizations compromised daily and heavy use of AI and automation, according to The Register.
- Later reports said Microsoft's Digital Crimes Unit disrupted the EvilTokens operation in September 2026, after a months-long run affecting thousands of inboxes.
How device code phishing works
The device code flow is a legitimate sign-in method for devices without keyboards (smart TVs, printers, CLI tools). The device shows a code; the user enters it at a Microsoft URL on another device and signs in.
In device code phishing:
- The attacker starts a device code sign-in and receives a code.
- They send the victim a message — email, chat, document — asking them to enter the code at the genuine Microsoft page.
- The victim signs in and completes MFA themselves.
- The attacker's session receives the tokens.
Because the victim uses the real Microsoft site and performs MFA, standard phishing defenses and MFA don't stop it.
What to do now
- Block device code flow with Conditional Access for everyone except documented exceptions.
- Train users: never enter a code someone sent you into a Microsoft sign-in page.
- Monitor sign-ins using the device code authentication protocol.
- Require compliant devices for sensitive resources, which limits token use from attacker machines.
Sources
- How to Block Device Code Flow With Conditional Access How-To & Hardening
- Detecting Device Code Phishing: Defender XDR and Sentinel Hunting Queries Detection & Response
- CIO Brief: The Phishing Attack Where Users Complete MFA for the Attacker CIO Briefings