A new phishing-as-a-service (PhaaS) campaign is exploiting Microsoft’s device password authentication flow to gain unauthorized access to user accounts. Sekoia researchers first identified the “ EvilTokens ” tool , which allows attackers to capture authentication tokens, tricking users into completing a legitimate sign-in process to the Microsoft environment.
See also: Dutch Police: Breach via phishing attack

The activity, observed since at least mid-February, relies on social engineering techniques that trick victims into entering a device code on a real Microsoft login page, Sekoia researchers noted in a blog post. “To compromise Microsoft 365 accounts, EvilTokens pages rely on device code phishing, a technique that differs from the common AitM tactic of replicating Microsoft authentication pages,” the researchers said.
The PhaaS tool offers a range of capabilities to its partners, including modules for access manipulation, email harvesting, identification capabilities, and a built-in webmail interface, all supported by AI automation, the researchers added. EvilTokens was found operating through bots on Telegram, with a dedicated channel for tool upgrades.
The campaign has primarily affected countries such as the US, Australia, Canada, France, India, Switzerland, and the UAE. The campaign focuses on exploiting Microsoft’s device authorization flow, a feature designed to simplify logins for devices such as smart TVs or command-line tools. EvilTokens reuses this workflow by generating a legitimate device code and then tricking victims into entering it themselves on the official login page.
See also: GitHub Phishing: Fake OpenClaw tokens to steal crypto wallets

Once the victim completes authentication, the attacker receives access tokens associated with the session. These tokens can then be used to access Microsoft 365 services, including email and cloud resources, without triggering typical credential-based notifications.
The Sekoia researchers noted that this technique bypasses many conventional phishing detections. Because authentication occurs on a legitimate Microsoft domain, there is no credential interception in transit, and multi-factor authentication is completed as it would in a normal login flow. The attack results in a form of account takeover that derives from seemingly expected user behavior.
Beyond the initial access vector, EvilTokens is structured as a complete phishing platform. The tool provides partners with ready-made baits, infrastructure, and automation tools designed to perform both the phishing phase and post-breach activity. Baits used in the campaign include fake SharePoint, DocuSign , and account notifications, all aimed at prompting users to enter device codes.
See also: Device code phishing attack has targeted 340+ organizations

Once access is gained, the platform allows for analysis of incoming traffic, allowing attackers to identify high-value targets, such as financial conversations or invoice threads.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
