
By Assaf Morag, Cybersecurity Researcher
As competition in the underground phishing market increases, so does the quality of the products and services offerings, particularly among the Phishing as a Service (PhaaS) category. EvilTokens is completely reshaping how PhaaS affiliate programs operate: rather than offering initial access alone, it also provides malicious analytics services informed by operator experience and AI-driven insights. PhaaS affiliate programs operate as their offering extends not only to provide initial access, but it also provides malicious analytics services which are based on experience and AI.
EvilTokens offers its customers token capture and analysis services over the compromised data to identify the most valuable data suitable for fraud and scam campaigns. It is PhaaS with a built-in post-compromise playbook: initial access, reconnaissance, and fraud preparation delivered as a single subscription. First documented in February 2026 and sold through Telegram at $1,500 for panel access plus $500 per month, EvilTokens has already been linked to campaigns affecting 344 organizations across five countries in a 16-day wave.
FAQ About EvilTokens
- How does EvilTokens make the phishing operation easier for threat actors?: After a phishing attack succeeds, EvilTokens helps attackers take control of the compromised account and guides them through the next steps toward financial fraud, instead of requiring them to decide how to use the stolen access on their own.
- How does EvilTokens trick its victims?: Its best documented technique abuses Microsoft’s legitimate device authorization flow, so the victim may complete a genuine sign-in and MFA while approving the attacker’s session.
- Is EvilTokens evolving?: EvilTokens is still changing quickly. Public research confirms important parts of its operation, but some newer functions remain operator claims.
Identity Threat Intelligence
Detect PhaaS Operations Targeting Your Organization Before Campaigns Launch
EvilTokens was advertised, sold, and supported on Telegram months before researchers documented 344 affected organizations. Flare continuously monitors these underground channels and dark web forums to detect when your brand is impersonated, when stolen session tokens surface for sale, and when PhaaS operators shift their targeting, giving your team lead time before the first lure reaches an inbox.
What is EvilTokens?
EvilTokens is a Microsoft-focused PhaaS operation sold primarily through Telegram, first documented in February 2026. Its core target, Office365 capture product was advertised at $1,500 for panel access, followed by a $500 monthly payment that kept the phishing links and backend connection active.
Like other PhaaS platforms, EvilTokens simplifies the phishing operation and offers a subscription-based model that provides a maintained environment, which is backed by tutorials, onboarding, and customer support. EvilTokens goes beyond that and also provides analytics services that help its affiliates understand how to optimize the value from a compromised account. For example, what distinguishes it is the layer that comes after the initial compromise: analytics services that help affiliates extract maximum value from a compromised account by examining emails and business conversations to identify trusted contacts, pending payments, and exploitable opportunities.

Flare screenshot of the EvilTokens Telegram channel (Flare link to post, sign up for the free trial to access if you aren’t already a customer)
How the Device-Code Attack Works
Device authorization is a legitimate OAuth 2.0 process for devices that cannot conveniently accept a full login. EvilTokens turns the separation between the device and the person approving it into a phishing opportunity. The attack flow:
- A lure leads the victim to a page controlled by EvilTokens.
- The page generates a fresh Microsoft device code and then opens Microsoft’s real device-login site.
- The victim enters the code and completes the normal authentication process, including MFA.
- Microsoft issues tokens to the session initiated by the attacker.
The password is not stolen, and MFA works as expected. However, the deception lies in the fact that the victim is unknowingly authorizing the attacker’s session on another device.

EvilToken’s attack flow
A Microsoft device code is valid for only 15 minutes. If the attacker created it when sending the phishing email, it might expire before the victim opened the message. EvilTokens avoids this problem by creating a new code only after the victim opens the phishing page, ensuring that the code is still valid when the victim is prompted to enter it.
Why EvilTokens Goes Beyond Token Capture
The evolution follows a pattern visible in the legitimate business world. Data is often referred as the new gold, and when the cost of data collection drops to near zero, the value shifts from acquiring data to analyzing it. The same logic now applies to phishing operations.
Earlier generations of PhaaS reduced the cost and complexity of launching campaigns. As a result, successful affiliates now collect large volumes of compromised access, but turning that access into revenue still requires skill: understanding what is in an inbox, identifying which contacts can be exploited, and crafting convincing follow-up messages. EvilTokens automates that entire chain.
Specifically, the platform:
- Searches compromised inboxes for financial information (invoices, payment requests, pending transactions)
- Identifies key stakeholders (suppliers, decision-makers, payment approvers)
- Maps business logic (approval workflows, transaction patterns, communication norms)
- Generates fraudulent messages using AI to produce convincing follow-up communications targeting the contacts and relationships it discovers
The result is an automated process that transforms raw account access into a complete, AI-assisted fraud chain without requiring the affiliate to manually read through thousands of emails or craft convincing social engineering messages.
We actually see the same processes in the underground. In the past, phishing services were offered to design the front hand, develop the backend and they ultimately consolidated into a phishing kit, then mass production to reach as many victims as possible, then Phishing as a Service, with an entire orchestration of the phishing process. But now a new problem starts, when the cost and complexity of a campaign drops to minimum, lots of data is collected, and when the access is limited, this data needs to be consumed, analyzed and transform into “business decisions,” so the same legitimate logic applies here and now we see these new services arise.
In that sense, EvilTokens helps attackers find the most valuable pieces of information to generate a successful fraudulent attack. From the vast volume of email data, EvilTokens search for financial related information (i.e. invoices and payments), stakeholders (suppliers, decision takers, those who approve payments), past transactions, business logic, payment processes etc. AI-based processes summarize the data. AI-based processes generate convincing fraudulent messages. Thus, an automated process generates a complete highly convincing AI-powered attack chain.
Evidence of Scale and Continued Evolution
EvilTokens was broadly covered in recent news:
- Sekoia documented active phishing pages and backend infrastructure. The research shows how 66 email attachments led victims to EvilTokens pages, while its infrastructure searches returned more than 1,000 related results.
- Huntress reported a 16-day wave affecting 344 organizations across five countries. These measurements come from different sources and should not be treated as one victim total, but both indicate that adoption moved quickly beyond private advertising.
- Cisco Talos analyzed an affiliate panel called ARToken that shared infrastructure and operational patterns with EvilTokens, exposing a more mature post-compromise environment and stronger anti-analysis controls. The overlap supports a close relationship.
These measurements come from different sources and methodologies and should not be combined into a single victim total. However, both indicate that adoption moved quickly beyond private advertising into active campaigns at scale.
Recommendations for Security Teams
- Restrict device-code authentication to approved use cases. If your organization does not depend on the OAuth 2.0 device authorization flow, consider disabling it. Where it is required, enforce access controls through Conditional Access or equivalent identity-provider policies and limit its use to trusted users, devices, or applications.
- Increase visibility into device-code activity. Because device-code authentication is uncommon in many enterprise environments, generate alerts for unexpected device-code grants, new authorizations, unusual token issuance, or authentication attempts from unfamiliar devices, IP addresses, or geographic locations.
- Limit the value of stolen tokens. Reduce token persistence by enforcing shorter access and refresh token lifetimes where practical, require periodic reauthentication for high-value applications, and immediately invalidate active sessions following suspected account compromise.
- Educate users about modern phishing techniques. Employees should understand that authenticating on a legitimate Microsoft or identity-provider login page does not necessarily mean the request itself is legitimate. Unexpected device codes, approval prompts, verification requests, or consent dialogs should always be treated with caution and reported.
- Continuously monitor identity activity. Review authentication events across Microsoft Entra ID, Google Workspace, Okta, AWS, and other identity providers for anomalous sign-ins, abnormal application consent, unexpected device enrollments, token reuse, mailbox rule creation, or suspicious access to cloud resources.
- Act quickly when compromise is suspected. Revoke active sessions and authentication tokens, rotate affected credentials, remove unauthorized devices and application permissions, and investigate any actions performed using the compromised identity to determine the scope of the incident.
- Track the underground ecosystem for early warning. Phishing-as-a-Service (PhaaS) operations are frequently advertised, updated, and supported within cybercrime communities. Monitoring these environments for brand impersonation, infrastructure changes, leaked assets, and operator discussions can provide advance warning of campaigns targeting your organization before they reach end users.
Defending Against PhaaS
EvilTokens represents a structural shift in the PhaaS market. Previous platforms commoditized the front end of the attack: the lure, the landing page, the credential capture. EvilTokens commoditizes what comes after. By automating inbox analysis, stakeholder mapping, and AI-generated fraud messages, it removes the skill barrier that once separated a captured token from a successful financial compromise. An affiliate no longer needs to understand business email compromise tradecraft, as the platform provides it as a feature.
The device-code phishing technique at its core is particularly difficult to defend against because it does not rely on fake login pages or credential interception. The victim authenticates on Microsoft’s real infrastructure, completes real MFA, and sees no obvious indicator of compromise. Defense must therefore shift upstream, to restricting the device-code flow itself, detecting anomalous token grants, and monitoring for the post-compromise behaviors (bulk inbox access, rule creation, outbound impersonation) that follow a successful attack.
For security teams, EvilTokens is a signal of where the PhaaS market is heading. As initial access becomes cheaper and more automated, the competitive advantage moves to post-compromise services: the analytics, the AI-generated content, and the fraud playbooks that turn raw access into revenue. Organizations that focus their detection exclusively on the phishing email itself are defending against the previous generation of the threat. The current generation operates after the inbox is already compromised, and it moves fast.
Identity Threat Intelligence
Detect PhaaS Operations Targeting Your Organization Before Campaigns Launch
EvilTokens was advertised, sold, and supported on Telegram months before researchers documented 344 affected organizations. Flare continuously monitors these underground channels and dark web forums to detect when your brand is impersonated, when stolen session tokens surface for sale, and when PhaaS operators shift their targeting, giving your team lead time before the first lure reaches an inbox.





