{"id":61401,"date":"2026-09-22T15:00:00","date_gmt":"2026-09-22T15:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/?p=149499"},"modified":"2026-09-22T15:00:00","modified_gmt":"2026-09-22T15:00:00","slug":"unmasking-eviltokens-getting-to-the-root-of-device-code-phishing","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/","title":{"rendered":"Unmasking EvilTokens: Getting to the root of device code phishing"},"content":{"rendered":"<aside class=\"table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents\" id=\"accordion-aa1bfd02-13ab-499b-a88f-4c4c59fadfc1\" data-bi-an=\"table-of-contents\"> <button class=\"btn btn-collapse\" type=\"button\" aria-expanded=\"true\" aria-controls=\"accordion-collapse-aa1bfd02-13ab-499b-a88f-4c4c59fadfc1\"> <span class=\"table-of-contents-block__label\">In this article<\/span> <span class=\"table-of-contents-block__current\" aria-hidden=\"true\"><\/span> <svg class=\"table-of-contents-block__arrow\" aria-label=\"Toggle arrow\" width=\"18\" height=\"11\" viewBox=\"0 0 18 11\" fill=\"none\"> <path d=\"M15.7761 11L18 8.82043L9 0L0 8.82043L2.22394 11L9 4.35913L15.7761 11Z\" fill=\"currentColor\" \/> <\/svg> <\/button> <span class=\"table-of-contents-block__progress-bar\"><\/span><br \/>\n<\/aside>\n<p class=\"wp-block-paragraph\">Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets. This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide.<\/p>\n<p class=\"wp-block-paragraph\">EvilTokens enabled threat actors to abuse the device code authentication flow, steal tokens, and compromise organizational accounts at scale using an AI-driven infrastructure and automating multiple parts of the attack chain. The toolkit offered a plethora of prebuilt phishing templates and landing pages with an AI-powered assistant to aid in structuring target-specific emails.<\/p>\n<p class=\"wp-block-paragraph\">Stolen tokens are used for email exfiltration and persistence, often through the creation of malicious inbox rules that conceal communications. In some cases, tokens can also be used to grant new devices access to a victim\u2019s inbox, a particularly durable method to maintain persistence. Microsoft Threat Intelligence tracks the threat actor behind the development and support of the EvilTokens phish kit as Storm-2992.<\/p>\n<p class=\"wp-block-paragraph\">Post-compromise, EvilTokens enabled threat actors to utilize AI assistants to sift through victim mailbox activity and engineer a phishing message based on the accessible email content. EvilTokens also allowed threat actors to conduct Microsoft Graph reconnaissance to map organizational structure and permissions, enabling continued access and potential lateral movement while tokens remain valid. While token-targeting phishing is not new, it has become far more common and industrialized over the last several years as organizations adopted multifactor authentication (MFA).<\/p>\n<p class=\"wp-block-paragraph\">To evade detection, EvilTokens uses a multi-stage delivery pipeline designed to bypass traditional email gateways and endpoint security. Targets are lured through deceptive emails that use 44 different themes, including invoices and request for proposals (RFPs), or shared files. These emails contained malicious URLs, PDF attachments, and HTML files.<\/p>\n<p class=\"wp-block-paragraph\">Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, <a href=\"https:\/\/aka.ms\/ETDisruption\">Microsoft\u2019s Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">This blog provides a comprehensive, up-to-date analysis of the EvilTokens platform and operations. We share specific examples of the EvilTokens service panel and a detailed analysis of EvilTokens infrastructure. Defending against EvilTokens and similar adversary-in-the-middle (AiTM) phishing threats requires a layered approach that blends technical controls with user awareness. This blog also provides <a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender<\/a> detection and hunting guidance, as well as resources on how to set up mail flow rules, enforce spoof protections, and configure third-party connectors to prevent spoofed phishing messages from reaching user inboxes.<\/p>\n<h2 class=\"wp-block-heading\" id=\"what-is-device-code-phishing\">What is device code phishing?<\/h2>\n<p class=\"wp-block-paragraph\">One of the primary capabilities of EvilTokens is its device code phishing flow, which abuses <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity-platform\/v2-oauth2-device-code\" target=\"_blank\" rel=\"noreferrer noopener\">device code authentication<\/a>, a legitimate OAuth flow designed for devices with limited interfaces, such as smart TVs, printers, <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/policy-teams-devices-device-code-flow\" target=\"_blank\" rel=\"noreferrer noopener\">Teams devices, and conferencing devices<\/a>, that cannot support a standard interactive sign-in. In this model, a user is presented with a short code on the device they are trying to sign in from and is instructed to enter that code into a browser on a separate device to complete authentication.<\/p>\n<p class=\"wp-block-paragraph\">While this flow is useful for these scenarios, it introduces a security tradeoff. Because authentication is completed on a separate device, the session initiating the request is not strongly bound to the user\u2019s original context. Threat actors have abused this characteristic as a way to circumvent traditional MFA protections by decoupling authentication from the originating session. Threat actors also use social engineering layouts and other tricks to disguise the legitimate device code flow approval as something else required.<\/p>\n<p class=\"wp-block-paragraph\">Device code phishing occurs when threat actors insert themselves into this process. Instead of a legitimate device requesting access, the threat actor initiates the flow and provides the user with a code through a phishing lure. When the user enters the code, they unknowingly authorize the threat actor\u2019s session, granting access to the account without exposing credentials. Microsoft recommends <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/identity\/conditional-access\/policy-teams-devices-device-code-flow\" target=\"_blank\" rel=\"noreferrer noopener\">blocking device code flow<\/a> wherever possible. If your organization uses Teams devices that require device code flow, scope the exception to specific Teams device resource accounts and exclude the Device Registration Service resource from your Conditional Access policy.<\/p>\n<p class=\"wp-block-paragraph\">In April 2026, Microsoft tracked <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/04\/06\/ai-enabled-device-code-phishing-campaign-april-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">a phishing campaign aligned with EvilTokens<\/a> that used automation platforms to spin up thousands of unique, short-lived polling nodes. This approach allowed the threat actors to deploy complex backend logic (Node.js) that bypassed traditional signature-based or pattern-based detection. This infrastructure was leveraged in the attack end-to-end, from generating dynamic device codes to post-compromise activities.<\/p>\n<p class=\"wp-block-paragraph\">The following sections examine how EvilTokens operated, the capabilities available through its customer panel, and infrastructure supporting phishing campaigns. We also trace the EvilTokens attack chain, from lure delivery and device code generation through defense evasion, token theft, and post-compromise activity.<\/p>\n<h2 class=\"wp-block-heading\" id=\"eviltokens-platform-and-operations\">EvilTokens platform and operations<\/h2>\n<h3 class=\"wp-block-heading\" id=\"distribution-and-affiliate-support\">Distribution and affiliate support<\/h3>\n<p class=\"wp-block-paragraph\">The threat actor tracked as Storm-2992 advertised and sold EvilTokens services to cybercriminals on the actor\u2019s Telegram channels. Cybercriminals continue to gravitate towards apps like Telegram that provide anonymity, cross-platform access, file sharing, and channels for broadcasting announcements to large groups of followers. The threat actor uses Telegram to advertise their phish kit, announce updates, coordinate with their subscribers, and provide customer support.<\/p>\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"465\" height=\"1008\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1.jpg\" alt=\"Screenshot of the EvilTokens Telegram bot\" class=\"wp-image-149523\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1.jpg 465w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1-138x300.jpg 138w\" sizes=\"auto, (max-width: 465px) 100vw, 465px\"><figcaption class=\"wp-element-caption\"><em>Figure 1. EvilTokens Telegram bot<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">EvilTokens phish kits are sold at $1,500 USD for initial purchase, with a monthly subscription fee of $500 for continued access to the kit and control panel. The kit provides additional products, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender. Each of these products has additional fees for 30 days of access.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig2a-EvilTokens-store-bot-1.webp\" alt=\"Screenshots of the EvilTokens store bot\" class=\"wp-image-149524 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig2a-EvilTokens-store-bot-1.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 2. EvilTokens Telegram store bot <\/em><\/figcaption><\/figure>\n<h3 class=\"wp-block-heading\" id=\"customer-panel-and-campaign-configuration\">Customer panel and campaign configuration<\/h3>\n<p class=\"wp-block-paragraph\">The EvilTokens panel provides the core components needed to support phishing campaigns, including pre\u2011built templates, attachment files for common lure formats, domain and hosting configuration, redirect logic, and victim tracking.<\/p>\n<p class=\"wp-block-paragraph\">After signing in, EvilTokens subscribers are presented a dashboard with various options to choose from. First, subscribers are asked to choose a deployment method (Cloudflare Workers\/Bunny or PHP Hosting) and then are asked to choose from a list of deploy options, including Capture Mode, Layout &amp; Template, Code Display Style, Page Language, CAPTCHA, AI Mode, and Captured Text. These options allow subscribers to highly customize their deployment methods.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"672\" height=\"567\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig3-EvilTokens-platform-welcome-page-1.jpg\" alt=\"Screenshot of the EvilTokens platform welcome page\" class=\"wp-image-149525\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig3-EvilTokens-platform-welcome-page-1.jpg 672w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig3-EvilTokens-platform-welcome-page-1-300x253.jpg 300w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\"><figcaption class=\"wp-element-caption\"><em>Figure 3. EvilTokens platform welcome page<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Subscribers are provided with multiple settings and additional guidance for managing captured tokens. Once tokens have been captured, EvilTokens offers its subscribers full access to the victim email account, as well as admin detection, token auto-refresh, and an auto-scan of inboxes using keyword alerts through Telegram.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"672\" height=\"464\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig4-EvilTokens-platform-options-1.jpg\" alt=\"Screenshot of the EvilTokens platform showing options for managing captured tokens\" class=\"wp-image-149526\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig4-EvilTokens-platform-options-1.jpg 672w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig4-EvilTokens-platform-options-1-300x207.jpg 300w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\"><figcaption class=\"wp-element-caption\"><em>Figure 4. EvilTokens platform options for managing captured tokens<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The toolkit offers additional products, which are detailed under Essential Tools. Here, subscribers are given product information and are provided with a link to download or get the product as well as a video tutorial. Subscribers are even given the opportunity to receive cryptocurrency as a reward for referring the service to others.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"672\" height=\"376\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig5-EvilTokens-Essential-Tools-1.jpg\" alt=\"Screenshot of EvolTokens Essential Tools page\" class=\"wp-image-149527\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig5-EvilTokens-Essential-Tools-1.jpg 672w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig5-EvilTokens-Essential-Tools-1-300x168.jpg 300w\" sizes=\"auto, (max-width: 672px) 100vw, 672px\"><figcaption class=\"wp-element-caption\"><em>Figure 5. EvilTokens Essential Tools page<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">The platform offers 44 different themes for customizing email templates and landing pages, including text and colors.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"465\" height=\"582\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig6-EvilTokens-templates-1.jpg\" alt=\"Screenshot of EvilTokens template themes\" class=\"wp-image-149528\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig6-EvilTokens-templates-1.jpg 465w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig6-EvilTokens-templates-1-240x300.jpg 240w\" sizes=\"auto, (max-width: 465px) 100vw, 465px\"><figcaption class=\"wp-element-caption\"><em>Figure 6. EvilTokens template themes<\/em><\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"eviltokens-phishing-emails\">EvilTokens phishing emails<\/h2>\n<p class=\"wp-block-paragraph\">EvilTokens offers subscribers personalized lures, using AI to create targeted phishing emails aligned to the target\u2019s role, including the use of various themes to increase the likelihood of user interaction. Themes used include document signing services, Microsoft cloud services, third-party services (cloud identity, file hosting, payment\/invoicing), and other miscellaneous services like voicemail and eFax.<\/p>\n<p class=\"wp-block-paragraph\">Additionally, researchers at Huntress noted email content like construction bid proposals, business partnership agreements, employee compensation\/benefits, and password expiring notices in EvilTokens emails.<\/p>\n<h3 class=\"wp-block-heading\" id=\"eviltokens-phishing-sequence\">EvilTokens phishing sequence<\/h3>\n<p class=\"wp-block-paragraph\">The attack chain begins when a user interacts with a malicious attachment or URL embedded within a high-pressure lure (for example, \u201cAction Required: Password Expiration\u201d).<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig7-EvilTokens-phishing-email-1.webp\" alt=\"Screenshot of a sample EvilTokens phishing email\" class=\"wp-image-149540 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig7-EvilTokens-phishing-email-1.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 7. Example of an EvilTokens phishing email<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">When a user clicks the malicious link or attachment, they are directed to a web page running a background automation script. This script interacts with the Microsoft identity provider in real time to generate a live device code. This code is then displayed on the user\u2019s screen with a \u201cCopy Code\u201d button along with a \u201cContinue\u201d or \u201cContinue with Microsoft\u201d button that, when clicked, redirects to the official <em>microsoft.com\/devicelogin<\/em> portal. <\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig8-EvilTokens-sample-generated-device-code-1.webp\" alt=\"Screenshot of a sample device code\" class=\"wp-image-149529 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig8-EvilTokens-sample-generated-device-code-1.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 8. Example of generated device code<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">After presenting the code to the user and opening the legitimate <em>microsoft.com\/devicelogin<\/em> URL, the script enters a polling state using the <em>checkStatus()<\/em> function to monitor the 15-minute window in real time. Every three to five seconds (<em>setInterval<\/em>), the script pings the threat actor\u2019s <em>\/state<\/em> endpoint. It sends the secret session identifier code to validate if the user has authenticated yet. While the targeted user is entering the code on the real Microsoft site, the loop returns a \u201cpending\u201d status.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig9-Sample-device-code-sign-in-1.webp\" alt=\"Screenshot of Microsoft device code sign-in portal\" class=\"wp-image-149530 webp-format\" srcset data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig9-Sample-device-code-sign-in-1.webp\"><figcaption class=\"wp-element-caption\"><em>Figure 9. Example of Microsoft device code sign-in portal<\/em><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">To minimize user effort and maximize the success rate, the threat actor\u2019s script often automatically copies the generated device code to the user\u2019s clipboard. Once the user reaches the official sign-in page, they paste the code. If the user does not have an active session, they are prompted to provide their password and MFA. If they are already signed in, simply pasting the code and confirming the request instantly authenticates the threat actor\u2019s session in the backend.<\/p>\n<p class=\"wp-block-paragraph\">The final stage varies depending on the threat actor\u2019s specific objectives. In some instances, within 10 minutes of the breach, threat actors registered new devices to generate a Primary Refresh Token (PRT) for long-term persistence. In other scenarios, they waited several hours before creating malicious inbox rules or exfiltrating sensitive email data to avoid immediate detection.<\/p>\n<p class=\"wp-block-paragraph\">EvilTokens adds the capability for threat actors to phish and take actions that they would not be capable of performing without EvilTokens tools assisting them, giving threat actors the ability to mass-phish users and perform other operations at their leisure.<\/p>\n<h3 class=\"wp-block-heading\" id=\"defense-evasion\">Defense evasion<\/h3>\n<p class=\"wp-block-paragraph\">EvilTokens uses a multi-stage delivery pipeline designed to bypass traditional email gateways and endpoint security. Phishing pages delivered to the user vary in complexity and evasion techniques, adding a customization layer by the operator and which tools they use. Popular techniques include but are not limited to image links (images that link to URLs), multi-stage redirection schemes, and attachments containing multi-stage delivery.<\/p>\n<p class=\"wp-block-paragraph\">Landing page evasions include fake CAPTCHA checks\/verification services that require user interaction before displaying the phishing content. To further evade automated URL scanners and sandboxes, the threat actors will at times not link directly to the final phishing site. Instead, they use a series of redirects through compromised legitimate domains and high-reputation \u201cserverless\u201d platforms. We observed heavy reliance on abuse of Vercel (<em>.vercel.app<\/em>), Cloudflare Workers (<em>.workers.dev<\/em>), and AWS Lambda for hosting the redirect logic. By using these domains, the phishing traffic blends in with legitimate enterprise cloud traffic, evading simple domain-blocklist triggers.<\/p>\n<h3 class=\"wp-block-heading\" id=\"post-compromise-account-access\">Post-compromise account access<\/h3>\n<p class=\"wp-block-paragraph\">Once authentication tokens are obtained, threat actors can focus on post-compromise activity designed to maintain and expand access and extract data. This access can be used to send further emails internally to the organization and to external contacts, allowing the actor to send phishing emails for seemingly trusted contacts. In one observed incident, the attack progressed to email exfiltration and account persistence through inbox rules created using Microsoft Office. This involved filtering the compromised users and selecting targets:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>High-value target identification:<\/strong> Using the EvilTokens AI capability, the threat actor reviewed and filtered for high-value targets\u2014specifically those in financial, executive, or administrative roles\u2014within the pool of compromised users.<\/li>\n<li class=\"wp-block-list-item\"><strong>Accelerated reconnaissance:<\/strong> After gaining access to Microsoft Graph for reconnaissance, the threat actor programmatically mapped internal organizational structures and identified sensitive permissions the moment a token was secured.<\/li>\n<li class=\"wp-block-list-item\"><strong>Targeted financial exfiltration:<\/strong> The most invasive activity was reserved for users with financial authority. For these specific profiles, the threat actors performed deep-dive reconnaissance into email communications, searching for high-value targets and sensitive information like wire transfer details, pending invoices, and executive correspondence.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"mitigation-and-protection-guidance\">Mitigation and protection guidance<\/h2>\n<p class=\"wp-block-paragraph\">To harden networks against the device code phishing activity described above, defenders can implement the following:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Only allow device code flow where necessary. Microsoft recommends <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/policy-block-authentication-flows\">blocking device code flow wherever possible<\/a>. Where necessary, configure Microsoft Entra ID\u2019s <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/concept-authentication-flows\">device code flow<\/a> in your Conditional Access policies.<\/li>\n<li class=\"wp-block-list-item\">Educate users about common phishing techniques. Sign-in prompts should clearly identify the application being authenticated to. As of 2021, Microsoft Azure interactions prompt the user to confirm (\u201cCancel\u201d or \u201cContinue\u201d) that they are signing in to the app they expect, which is an option frequently missing from phishing sign-ins. Be cautious of any \u201c[EXTERNAL]\u201d messages containing suspicious links. Do not sign in to resources from unfamiliar senders. <a href=\"https:\/\/support.microsoft.com\/en-us\/security\/protect-yourself-from-phishing\">Learn how to protect yourself from phishing.<\/a><\/li>\n<li class=\"wp-block-list-item\">Configure <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/anti-phishing-policies-about\">anti-phishing policies<\/a>. Anti-phishing policies protect against phishing attacks by detecting spoofed senders, impersonation attempts, and other deceptive email techniques.<\/li>\n<li class=\"wp-block-list-item\">Configure <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/safe-links-about\">Safe Links in Defender for Office 365<\/a>. Safe Links scanning protects your organization from malicious links that are used in phishing and other attacks. Safe Links can also enable high-confidence device code phishing alerts from Defender.<\/li>\n<li class=\"wp-block-list-item\">If suspected device code phishing activity is identified, follow the guidance on <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/responding-to-a-compromised-email-account?view=o365-worldwide\">responding to a compromised email account<\/a>. Additionally, <a href=\"https:\/\/learn.microsoft.com\/graph\/api\/user-revokesigninsessions\">revoke the user\u2019s refresh tokens by calling revokeSign-inSessions<\/a>. Consider <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/policy-all-users-persistent-browser#create-a-conditional-access-policy\">setting a Conditional Access Policy to force re-authentication<\/a> for users. (Observations from recent campaigns indicate that standard session revocation often only invalidates refresh tokens, leaving existing access tokens active for up to an hour. Given the hands-on nature of this threat, they frequently exploit this window of opportunity; consequently, we recommend temporarily disabling the compromised account to ensure immediate containment, despite the potential for brief business disruption).<\/li>\n<li class=\"wp-block-list-item\">Increase <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/anti-phishing-policies-about\">Advanced Phishing Threshold<\/a> to 2 or 3.<\/li>\n<li class=\"wp-block-list-item\">Enable <a href=\"https:\/\/learn.microsoft.com\/defender-office-365\/zero-hour-auto-purge\">Zero-hour auto purge (ZAP)<\/a> in Microsoft Defender for Office 365 to quarantine sent mail in response to newly acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.<\/li>\n<li class=\"wp-block-list-item\">Encourage users to use Microsoft Edge and other web browsers that support <a href=\"https:\/\/learn.microsoft.com\/deployedge\/microsoft-edge-security-smartscreen\">Microsoft Defender SmartScreen<\/a>, which identifies and blocks malicious websites, including phishing sites, scam sites, and sites that host malware.<\/li>\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-xdr\/alert-grading-playbook-inbox-manipulation-rules\">Create alerting of suspicious inbox-rule creation<\/a> to quickly identify and triage evidence of business email compromise (BEC) and phishing campaigns. This playbook helps defenders investigate any incident related to suspicious inbox manipulation rules configured by threat actors and take recommended actions to remediate the attack and protect networks.<\/li>\n<\/ul>\n<p class=\"wp-block-paragraph\">Microsoft recommends the following best practices to further help improve organizational defenses against phishing and other credential theft attacks:<\/p>\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/identity-protection\/howto-identity-protection-configure-risk-policies\" target=\"_blank\" rel=\"noreferrer noopener\">Implement a sign-in risk policy<\/a> to automate response to risky sign-ins. A sign-in risk represents the probability that a given authentication request is not authorized by the identity owner. A sign-in risk-based policy can be implemented by adding a sign-in risk condition to Conditional Access policies that evaluates the risk level of a specific user or group. Based on the risk level (high\/medium\/low), a policy can be configured to block access or force multifactor authentication.\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">When a user is a high risk and <a href=\"https:\/\/learn.microsoft.com\/entra\/identity\/conditional-access\/concept-continuous-access-evaluation\" target=\"_blank\" rel=\"noopener noreferrer\">Conditional Access evaluation is enabled<\/a>, the user\u2019s access is revoked, and they are forced to re-authenticate.<\/li>\n<li class=\"wp-block-list-item\">For regular activity monitoring, use <a href=\"https:\/\/portal.azure.com\/#view\/Microsoft_AAD_IAM\/SecurityMenuBlade\/~\/RiskySignIns\" target=\"_blank\" rel=\"noopener noreferrer\">Risky sign-in reports<\/a>, which surface attempted and successful user access activities where the legitimate owner might not have performed the sign-in.<\/li>\n<\/ul>\n<\/li>\n<li class=\"wp-block-list-item\">Require <a href=\"https:\/\/learn.microsoft.com\/microsoft-365\/admin\/security-and-compliance\/set-up-multi-factor-authentication\" target=\"_blank\" rel=\"noreferrer noopener\">multifactor authentication (MFA)<\/a>. Implementation of MFA remains an essential pillar in identity security and is highly effective at stopping a variety of threats. <\/li>\n<li class=\"wp-block-list-item\">Centralize your organization\u2019s identity management into a single platform. If your organization is a hybrid environment, integrate your on-premises directories with your cloud directories. If your organization is using a third-party for identity management, ensure this data is being logged in a SIEM or connected to Microsoft Entra to fully monitor for malicious identity access from a centralized location. The added benefit of centralizing all identity data is to facilitate implementation of <a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/manage-apps\/plan-sso-deployment\" target=\"_blank\" rel=\"noreferrer noopener\">Single Sign On (SSO)<\/a> and provide users with a more seamless authentication process, as well as configure Entra ID\u2019s machine learning models to operate on all identity data, thus learning the difference between legitimate access and malicious access quicker and easier. It is recommended to <a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/hybrid\/connect\/how-to-connect-password-hash-synchronization\" target=\"_blank\" rel=\"noreferrer noopener\">synchronize all user accounts<\/a> except administrative and high privileged ones when doing this to maintain a boundary between the on-premises environment and the cloud environment, in case of a breach.<\/li>\n<li class=\"wp-block-list-item\">If there are indications such as alerts that a user\u2019s refresh token is compromised, disable the device and revoke all existing refresh tokens. Disabling the device stops PRTs from working, and revoking the refresh tokens stops any refresh tokens that were issued using the PRT from working. Follow steps from <a href=\"https:\/\/learn.microsoft.com\/security\/operations\/token-theft-playbook\">Microsoft\u2019s token theft playbook<\/a> when responding to alerts related to compromised identities.<\/li>\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/architecture\/security-operations-introduction\">Secure accounts with credential hygiene<\/a>: practice the <a href=\"https:\/\/learn.microsoft.com\/azure\/active-directory\/roles\/delegate-by-task\">principle of least privilege<\/a> and audit privileged account activity in your Entra ID environments to slow and stop the threat actor.<\/li>\n<li class=\"wp-block-list-item\">Enable <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/enable-network-protection\">network protection<\/a> and <a href=\"https:\/\/learn.microsoft.com\/defender-endpoint\/web-protection-overview\">web protection<\/a> to prevent applications or users from accessing malicious domains and other malicious content on the internet.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"microsoft-defender-xdr-detections\">Microsoft Defender XDR detections<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/security\/business\/microsoft-defender\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender<\/a> customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog.<\/p>\n<p class=\"wp-block-paragraph\">Customers with provisioned access can also use Microsoft Security Copilot in Microsoft Defender to investigate and respond to incidents, hunt for threats, and protect their organization with relevant threat intelligence.<\/p>\n<p class=\"wp-block-paragraph\">Using Safe Links and Microsoft Entra ID Protection raises high-confidence device code phishing alerts from Defender.<\/p>\n<figure class=\"wp-block-table has-custom-table-width\" data-table-col-widths=\"[176,202,302]\">\n<table>\n<tbody readability=\"13.5\">\n<tr readability=\"2\">\n<td><strong>Tactic<\/strong> <\/td>\n<td><strong>Observed activity<\/strong> <\/td>\n<td><strong>Microsoft Defender coverage<\/strong> <\/td>\n<\/tr>\n<tr readability=\"4\">\n<td>Initial access<\/td>\n<td>Device code authentication<\/td>\n<td><strong>Microsoft Defender for Identity<\/strong> <br \/>\u2013 Anomalous OAuth device code authentication activity<\/td>\n<\/tr>\n<tr readability=\"7.5\">\n<td>Credential access<\/td>\n<td>Token theft following device code authentication<\/td>\n<td readability=\"6\"><strong>Microsoft Defender for Identity<\/strong> <br \/>\u2013 Anomalous token exchange following device code authentication <\/p>\n<p><strong>Microsoft Defender XDR<\/strong> <br \/>\u2013 User account compromise via OAuth device code phishing <br \/>\u2013 Suspicious Azure authentication through possible device code phishing<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"6\">\n<td>Persistence <\/td>\n<td>Device registration following anomalous device code authentication<\/td>\n<td readability=\"5\"><strong>Microsoft Defender for Identity<\/strong> <br \/>\u2013 Suspicious Entra device join or registration <\/p>\n<p><strong>Microsoft Defender XDR<\/strong> <br \/>\u2013 Device registration after potential device code phishing<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Discovery <\/td>\n<td>Anomalous volume of Microsoft Graph API requests following device code flow authentication <\/td>\n<td><strong>Microsoft Defender XDR<\/strong> <br \/>\u2013 Anomalous Microsoft Graph API activity after potential device code phishing <br \/>\u2013 Anomalous Microsoft Graph API POST activity after potential device code phishing<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td>Defense evasion<\/td>\n<td>Malicious inbox rule created after anomalous device code authentication<\/td>\n<td><strong>Microsoft Defender XDR<\/strong> <br \/>\u2013 Suspicious inbox rule created after potential device code phishing sign-in<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h3 class=\"wp-block-heading\" id=\"microsoft-security-copilot\">Microsoft Security Copilot<\/h3>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/security\/business\/ai-machine-learning\/microsoft-security-copilot\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Security Copilot<\/a> is <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-in-microsoft-365-defender\" target=\"_blank\" rel=\"noopener noreferrer\">embedded in Microsoft Defender<\/a> and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.<\/p>\n<p class=\"wp-block-paragraph\">Customers can also <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/security-copilot-agents-defender\">deploy AI agents<\/a>, including the following <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/agents-overview\">Microsoft Security Copilot agents<\/a>, to perform security tasks efficiently:<\/p>\n<p class=\"wp-block-paragraph\">Security Copilot is also available as a <a href=\"https:\/\/learn.microsoft.com\/en-us\/copilot\/security\/experiences-security-copilot\">standalone experience<\/a> where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers <a href=\"https:\/\/learn.microsoft.com\/copilot\/security\/developer\/custom-agent-overview\">developer scenarios<\/a> that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.<\/p>\n<h3 class=\"wp-block-heading\" id=\"threat-intelligence-reports\">Threat intelligence reports<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR customers can use the following <a href=\"https:\/\/learn.microsoft.com\/defender-xdr\/threat-analytics\">threat analytics<\/a> reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the malicious activity and techniques discussed in this blog. These reports provide intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft Security Copilot customers can also use either the Security Copilot standalone portal or in the <a href=\"https:\/\/learn.microsoft.com\/defender\/threat-intelligence\/using-copilot-threat-intelligence-defender-xdr\">embedded experience<\/a> in the Microsoft Defender portal to get more information about this threat.<\/p>\n<h2 class=\"wp-block-heading\" id=\"hunting-queries\">Hunting queries<\/h2>\n<p class=\"wp-block-paragraph\">Microsoft Defender XDR customers can use the following queries to detect possible phishing attempts. To explore up to 30 days\u2019 worth of raw data to inspect events in your network and locate potential EvilTokens-related indicators for more than a week, go to the <strong>Advanced hunting<\/strong> page &gt; <strong>Query<\/strong> tab, select the calendar dropdown menu to update your query to hunt for the <strong>Last 30 days<\/strong>.<\/p>\n<p class=\"wp-block-paragraph\">If a query provides high value insights into possible malicious or otherwise anomalous behavior, you can create a custom detection rule based on that query and surface those insights as custom alerts. To do this, run the query in the Advanced hunting page and select <strong>Create detection rule<\/strong>.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Suspicious URL clicked<\/strong> <\/p>\n<p class=\"wp-block-paragraph\">This query correlates Microsoft Defender for Office 365 signals and Microsoft Entra ID identity data to find the relevant endpoint event <em>BrowerLaunchedToOpen<\/em> in Microsoft Defender XDR. This event reflects relevant clicks on the malicious URL in the spear-phishing email recognized by Microsoft Defender for Office 365.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"34\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nAlertInfo\n| where ServiceSource =~ \"Microsoft Defender for Office 365\"\n| join (\nAlertEvidence\n| where EntityType ==\"Url\"\n| project AlertId, RemoteUrl )\non AlertId\n| join (\nAlertEvidence\n| where EntityType ==\"MailMessage\"\n| project AlertId, NetworkMessageId )\non AlertId\n\/\/ Get the unique NetworkMessageId for the email containing the Url\n| distinct RemoteUrl, NetworkMessageId\n| join EmailEvents on NetworkMessageId\n\/\/ Get the email RecipientEmailAddress and ObjectId from the email | distinct RemoteUrl, NetworkMessageId, RecipientEmailAddress , RecipientObjectId\n| join kind = inner IdentityInfo on $left.RecipientObjectId == $right.AccountObjectId | distinct RemoteUrl, NetworkMessageId, RecipientEmailAddress , RecipientObjectId, OnPremSid \/\/ Get the Url click event on the recipient device.\n| join kind = inner (DeviceEvents | where ActionType == \"BrowserLaunchedToOpenUrl\"| where isnotempty(RemoteUrl) | project UrlDeviceClickTime = Timestamp , UrlClickedByUserSid = RemoteUrl, InitiatingProcessAccountSid, DeviceName, DeviceId, InitiatingProcessFileName\n) on $left.OnPremSid == $right.InitiatingProcessAccountSid and $left.RemoteUrl == $right.UrlClickedByUserSid\n| distinct UrlDeviceClickTime, RemoteUrl, NetworkMessageId, RecipientEmailAddress, RecipientObjectId, OnPremSid, UrlClickedByUserSid, DeviceName, DeviceId, InitiatingProcessFileName | sort by UrlDeviceClickTime desc\n<\/pre>\n<\/div>\n<p class=\"wp-block-paragraph\"><strong>Determine successfully delivered phishing emails to Inbox\/Junk folder.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">This query identifies threats that were successfully delivered to Inbox\/Junk folder.<\/p>\n<div class=\"wp-block-syntaxhighlighter-code \" readability=\"16\">\n<pre class=\"brush: plain; auto-links: false; gutter: false; title: ; quick-code: false; notranslate\" title>\nEmailEvents\n| where isnotempty(ThreatTypes) and DeliveryLocation in~ (\"Inbox\/folder\",\"Junk folder\")\n| extend Name = tostring(split(SenderFromAddress, '@', 0)[0]), UPNSuffix = tostring(split(SenderFromAddress, '@', 1)[0])\n| extend Account_0_Name = Name\n| extend Account_0_UPNSuffix = UPNSuffix\n| extend IP_0_Address = SenderIPv4\n| extend MailBox_0_MailboxPrimaryAddress = RecipientEmailAddress\n<\/pre>\n<\/div>\n<h3 class=\"wp-block-heading\" id=\"microsoft-sentinel\">Microsoft Sentinel<\/h3>\n<p class=\"wp-block-paragraph\">Microsoft Sentinel customers can use the following queries to detect phishing attempts. These queries can help customers remain vigilant and safeguard their organization from phishing attacks:<\/p>\n<h3 class=\"wp-block-heading\" id=\"references\">References<\/h3>\n<h3 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h3>\n<p class=\"wp-block-paragraph\">For the latest security research from the Microsoft Threat Intelligence community, check out the <a href=\"https:\/\/aka.ms\/threatintelblog\">Microsoft Threat Intelligence Blog<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To get notified about new publications and to join discussions on social media, follow us on <a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-threat-intelligence\">LinkedIn<\/a>, <a href=\"https:\/\/x.com\/MsftSecIntel\">X (formerly Twitter)<\/a>, and <a href=\"https:\/\/bsky.app\/profile\/threatintel.microsoft.com\">Bluesky<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the <a href=\"https:\/\/thecyberwire.com\/podcasts\/microsoft-threat-intelligence\">Microsoft Threat Intelligence podcast<\/a>.<\/p>\n<p>READ MORE <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/22\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.<br \/>\nThe post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[10758,188],"class_list":["post-61401","post","type-post","status-publish","format-standard","hentry","category-microsoft-secure","tag-adversary-in-the-middle-aitm","tag-phishing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Unmasking EvilTokens: Getting to the root of device code phishing 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Unmasking EvilTokens: Getting to the root of device code phishing 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-22T15:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"432\" \/>\n\t<meta property=\"og:image:height\" content=\"435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"19 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Unmasking EvilTokens: Getting to the root of device code phishing\",\"datePublished\":\"2026-09-22T15:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/\"},\"wordCount\":3558,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Fig1-EvilTokens-Telegram-bot-1.jpg\",\"keywords\":[\"Adversary-in-the-middle (AiTM)\",\"Phishing\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/\",\"name\":\"Unmasking EvilTokens: Getting to the root of device code phishing 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Fig1-EvilTokens-Telegram-bot-1.jpg\",\"datePublished\":\"2026-09-22T15:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Fig1-EvilTokens-Telegram-bot-1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/en-us\\\/security\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Fig1-EvilTokens-Telegram-bot-1.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Adversary-in-the-middle (AiTM)\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/adversary-in-the-middle-aitm\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Unmasking EvilTokens: Getting to the root of device code phishing\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Unmasking EvilTokens: Getting to the root of device code phishing 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/","og_locale":"en_US","og_type":"article","og_title":"Unmasking EvilTokens: Getting to the root of device code phishing 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-09-22T15:00:00+00:00","og_image":[{"width":432,"height":435,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"19 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Unmasking EvilTokens: Getting to the root of device code phishing","datePublished":"2026-09-22T15:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/"},"wordCount":3558,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1.jpg","keywords":["Adversary-in-the-middle (AiTM)","Phishing"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/","url":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/","name":"Unmasking EvilTokens: Getting to the root of device code phishing 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1.jpg","datePublished":"2026-09-22T15:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#primaryimage","url":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1.jpg","contentUrl":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2026\/09\/Fig1-EvilTokens-Telegram-bot-1.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Adversary-in-the-middle (AiTM)","item":"https:\/\/www.threatshub.org\/blog\/tag\/adversary-in-the-middle-aitm\/"},{"@type":"ListItem","position":3,"name":"Unmasking EvilTokens: Getting to the root of device code phishing"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61401","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=61401"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/61401\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=61401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=61401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=61401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}