EvilTokens Turns Genuine Microsoft Login Into a Phishing Trap

The420.in Staff
5 Min Read

Cybercriminals are exploiting Microsoft’s device code sign-in feature through a phishing kit known as ‘EvilTokens’, turning a legitimate login process into a way to gain unauthorised access to user accounts.

Instead of simply stealing passwords through a fake login page, attackers can persuade victims to approve device codes through Microsoft’s genuine sign-in portal. Once approved, the process can potentially give attackers access tokens associated with the targeted account.

What Is EvilTokens?

EvilTokens is a phishing toolkit that Microsoft security researchers first observed in February 2026. Researchers linked the toolkit to a cybercriminal group tracked as Storm-2992.

According to Microsoft, campaigns involving EvilTokens compromised more than 12,000 inboxes across over 10,000 organisations worldwide. Financial services, construction, healthcare and education were among the affected sectors, with significant victim activity observed in countries including India, the United States, Canada, the United Kingdom, Australia and France.

How Does the Attack Begin?

Victims may first receive an urgent-looking email about an invoice, shared document, signature request or expiring password.

A link or attachment then directs the recipient to a page displaying a Microsoft device code and encourages the user to continue with the sign-in process.

EvilTokens can generate a fresh device code when the phishing page is opened, copy it to the victim’s clipboard and direct the user to Microsoft’s legitimate sign-in portal.

The technique is difficult to recognise because the victim may actually be interacting with Microsoft’s genuine sign-in page.

The attacker initiates the device login request and then persuades the victim to authenticate it. If the user completes the required password and multifactor authentication steps, or confirms an existing session, the attacker’s initiated session may become authenticated.

As a result, the phishing infrastructure does not necessarily need to directly collect the victim’s password.

What Happens After the Account Is Compromised?

Attackers may gain access to emails, search for financial or payment-related information and use the compromised mailbox to contact colleagues, customers or business partners.

EvilTokens reportedly also includes AI-powered capabilities that can generate phishing messages tailored to a victim’s job role and analyse captured email information for executives, finance staff and administrators.

Information from genuine business conversations could then be used to create more convincing fraudulent payment requests.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

How Is AI Being Used?

AI can make the phishing operation more targeted by helping attackers generate lures suited to particular employees and analyse compromised mailbox data.

Instead of sending only generic phishing emails, attackers can potentially identify employees involved in finance, administration or senior management and use information from genuine conversations to make later messages appear more credible.

How Is EvilTokens Being Sold?

The phishing kit is reportedly offered to other cybercriminals through Telegram for an initial price of $1,500, followed by a monthly fee of $500.

It provides ready-made themes, redirection options and victim-tracking capabilities. Attackers can also use deceptive image links, multiple redirects and fake verification checks before presenting the device-code sign-in request.

Can Attackers Keep Access After the Attack?

According to Microsoft, attackers may attempt to establish additional persistence after gaining access to an account.

This can include creating inbox rules that hide important messages or registering additional devices. In some observed cases, new devices were registered within 10 minutes of an account being compromised.

Researchers also observed thousands of short-lived automated network nodes in April, complicating efforts to trace the infrastructure supporting individual phishing campaigns.

How Can Users and Companies Stay Safe?

Microsoft has advised organisations to disable device code sign-in when it is not required and restrict exceptions where the feature remains necessary. Employees should never approve a device code for a login they did not initiate.

Security teams should also monitor unexpected sign-ins, newly registered devices and suspicious inbox rules. Where compromise is suspected, active tokens should be revoked and mailbox activity, registered devices and other indicators of unauthorised access should be investigated quickly.

The420 Takeaway: A Genuine Login Page Can Still Be Part of the Trap

A familiar Microsoft sign-in page should not automatically make an unexpected login request trustworthy. If you did not initiate a device-code login, do not approve it. Organisations should treat unexpected device registrations, unusual mailbox rules and unfamiliar sign-ins as warning signs requiring immediate investigation.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected