EvilTokens Uses AI to Tip Off Scammers After Stealing Microsoft Sessions

A new phishing service named EvilTokens is taking Microsoft 365 attacks to a more sophisticated level. Instead of merely stealing login credentials, this operation hijacks session tokens via a genuine Microsoft login flow. Then, post-compromise, it applies AI to comb through compromised mailboxes—locating invoices, pending transactions and key approvals—uncovering which contacts and conversations are most likely to yield successful financial fraud. The platform hands over these findings to attackers, helping them craft credible follow-up scams inside legitimate business correspondence. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

How EvilTokens’s Attack Chain Works

The initial phase hinges on OAuth device-code phishing. Victims are led to a controlled phishing page that generates a device code. They are then redirected to Microsoft’s legitimate sign-in interface, where they unknowingly authorize the attacker’s session. Although the login page is real and all credentials and multi-factor authentication are entered as usual, tokens are issued to the malicious party once approved. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

Once the attacker holds the session token, EvilTokens doesn’t stop. Its AI algorithms automatically review mailbox contents—searching for invoices, payment requests, past transactions, decision-makers and even typical approval language. Armed with this context, the attacker can zero in on someone influential in financial workflows or pretending to be a vendor or trusted contact. This lets them craft follow-up messages—fake invoice requests or urgent payment demands—that blend in with genuine company communication. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

Scope and Threat Landscape

The operation has made a swift impact. First observed in February 2026, EvilTokens is marketed primarily via Telegram. In one 16-day blitz, 344 organizations in five countries reported attacks. Separately, researchers found over 1,000 infrastructure indicators and dozens of malicious email attachments linked to EvilTokens phishing. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

This service lowers the barrier for fraud because users with basic knowledge of phishing can execute advanced business email compromise simply by applying the platform’s findings and tactics. It abstracts expertise, combining session theft, data extraction, and impersonation into a dangerous feature set. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

Defenses and Mitigations

EvilTokens exploits the trust users place in Microsoft’s legitimate user interfaces. By using Microsoft’s device-code system, it sidesteps traditional defenses tied to credential-based phishing and MFA bypass. Device codes issued during these attacks last for about 15 minutes, meaning timing is critical. The code is only generated when a target lands on the phishing page. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

To counter this threat, organizations should restrict or disable device-code authentication where it’s unnecessary. Monitoring unexpected device code approvals, anomalous new sessions or tokens, unexpected consent prompts, and odd login locations are key. Token lifetimes should be short, and compromised sessions must be revoked quickly to limit exposure. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

Users need education too. Just because the sign-in page is the real Microsoft portal doesn’t mean the request is legitimate. Suspicious prompts—unexpected codes or verification requests—should be treated with caution and reported, even if everything looks visually authentic. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

In addition, defenders should watch what happens after logins: look for large mailbox searches, suspicious new inbox rules, reuse of tokens, unusual cloud data access, and emails sent in someone else’s name. Detection shouldn’t end at the point of phishing delivery—it must chase the attacker’s activity well beyond. ([cybersecuritynews.com](https://cybersecuritynews.com/eviltokens-steal-microsoft-sessions/))

EvilTokens represents a new breed of phishing-as-a-service. The combination of session theft with post-login AI analysis redefines the threat landscape for organizations of every size—not just those traditionally targeted by sophisticated cybercrime. Teams that once focused on credential hygiene and MFA might now need to build out monitoring and response workflows deeper into account activity. Watch for how other platforms might adopt similar tactics—and the pressure this will put on identity infrastructure.