Threats · 178 days ago
A device-code phishing campaign has harvested persistent OAuth tokens from Microsoft 365 accounts at over 340 organizations across the U.S., Canada, Australia, New Zealand and Germany since February 2026.
5 sources covering this story
Inside an AI‑enabled device code phishing campaign | Microsoft Security Blog
A new wave of device code phishing shows how threat actors are scaling account compromise using AI and end‑to‑end automation.
New EvilTokens service fuels Microsoft device code phishing attacks
A new malicious kit called EvilTokens integrates device code phishing capabilities, allowing attackers to hijack Microsoft accounts and provide advanced features for business email compromise attacks.
EvilTokens ramps up device code phishing targeting Microsoft 365 users - Help Net Security
Device code phishing activity aimed at Microsoft 365 users is increasing due to EvilTokens, specialized toolkit offered as-a-service.
New widespread EvilTokens kit: device code phishing as-a-service
Uncover the new sophisticated EvilTokens device code phishing as-a-service, with AI-augmented features facilitating BEC fraud
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
Device code phishing targets 340+ Microsoft 365 orgs since Feb 2026 via OAuth abuse, enabling persistent token hijacking and account takeover.
Part of the PlainSec briefing for 2026-04-01