Sekoia.io's recent research exposes EvilTokens, a widespread Phishing-as-a-Service (PhaaS) kit that runs device-code phishing against Microsoft 365. The campaign uses trusted brand lures (DocuSign, Microsoft 365, Adobe) hosted on disposable Cloudflare Workers infrastructure.

Instead of harvesting passwords, the kit abuses Microsoft's OAuth device authorization grant: it tricks the victim into approving the attacker's device on the genuine Microsoft sign-in flow, bypassing both credential-phishing defenses and MFA. The page content is AES-GCM encrypted and decrypted in-browser to evade static analysis.
The EvilTokens campaign is significant because:

Zimperium's Mobile Threat Defense (MTD) detects and blocks the EvilTokens phishing URLs directly on the mobile device, stopping the lure at the entry point before the victim ever reaches the device-code step. On top of this, our research team identified hundreds of new domains actively using this phishing kit. These IOCs can be found in the following Github repository.
© 2026 Zimperium. All Rights Reserved. Privacy Settings Modern Slavery Act Statement