There is no fake page. No password form. No spelling mistake giving away the scam. The victim visits the genuine Microsoft website, enters a real code, and the attacker still ends up with full access to their Microsoft 365 account. This is not a flaw in Microsoft's security — it is the system working exactly as designed, used in the wrong direction.

It is called EvilTokens, and it represents the most consequential shift in phishing technique in years: instead of stealing passwords, it steals already-authenticated sessions.

Imagen del artículo

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

How the attack works, step by step

EvilTokens abuses a legitimate Microsoft mechanism called the OAuth 2.0 Device Authorization Grant (also known as device code flow). This system was originally designed for devices without a full keyboard or convenient browser — a smart TV, a games console, a command-line tool — where the user signs in by entering a short code on another device with a browser.

The attack follows this sequence:

1. Reconnaissance: Microsoft has observed this preparation phase running 10 to 15 days ahead of the actual phishing attempt, during which attackers study the target and prepare the lure.

2. The lure: The victim receives an email or message disguised as an invoice, a shared document, a calendar invite or a SharePoint access request. The wording is usually simple: "Verify to view" or "Signature required".

3. The decoy page: When the victim clicks through, they land on a page impersonating a trusted brand or service. That page requests a device code from Microsoft.

4. The trap code: The page shows the victim a code and points them to the genuine Microsoft portal, microsoft.com/devicelogin. The code is valid for only 15 minutes — the time pressure is part of the attack's design.

5. The fatal authorisation: The victim enters the code on the real Microsoft page. The catch is that the code does not belong to their own session — it belongs to the session the attacker previously initiated. Without realising it, the victim is authorising the attacker's device, not their own.

6. Handing over the keys: Seeing a valid sign-in, Microsoft issues access and refresh tokens to the session opened by the attacker. The attacker gains full access to the account without ever seeing a password.

Why this attack is so effective

EvilTokens strips out nearly every classic red flag that security awareness training has taught for years: no misspelled domains, no fake login pages, no suspicious password form. The login page is real. From the victim's perspective, the entire authentication process appears to work exactly as expected.

Two-factor authentication does not protect against this scenario either. Attackers need no technical wizardry to defeat 2FA — they simply trick the victim into completing the verification process on their behalf. The victim approves the wrong session, and 2FA does exactly what it was asked to do: authenticate.

As one Microsoft threat intelligence lead put it: the user is doing something that feels totally normal. Nothing about the process feels suspicious or resembles traditional credential theft.

Phishing as a product: the EvilTokens business model

EvilTokens is not an isolated campaign from a single group. It is a full Phishing-as-a-Service (PhaaS) platform, sold through Telegram for $1,500 plus a $500 monthly maintenance fee. It includes complete attack infrastructure: AI-generated lures, dynamic code generation and post-compromise automation.

Artificial intelligence has closed the last gap that previously limited this type of attack: it generates role-specific lures at machine speed, eliminates the timing window that previously constrained the viability of device code attacks, and drafts convincing wire fraud emails written in the victim's own voice within minutes of capturing the token.

The result is that anyone with a budget — no technical skill required — can launch session-theft campaigns at industrial scale.

The paradigm shift: from passwords to identity

This type of attack represents a structural shift in how account security needs to be thought about. For years, defence has centred on protecting the password: password managers, multi-factor authentication, training to spot fake login pages. EvilTokens completely bypasses that layer of defence because it never needs the password — it goes straight for the already-authenticated session.

This means "we have MFA enabled" is no longer a complete answer to whether an account is protected. Token-aware monitoring and phishing-resistant authentication methods become essential against this kind of threat.

Warning signs and what to do

Although the attack is designed to look normal, there are signs a trained user can pick up on:

The underlying lesson

EvilTokens is a reminder that attackers don't always need to break down the front door or steal the key. Sometimes they only need to convince someone to open it themselves. Classic security advice — "check the link", "look for spelling mistakes" — remains useful, but it is no longer enough against attacks that abuse legitimate authentication processes instead of faking them.

If your organisation has detected suspicious sign-in activity or suspects an account has been compromised through session theft, Oscar Orts — a certified judicial computer expert — can forensically analyse the incident and issue an expert report with full legal validity for court proceedings or insurance claims.