EvilTokens Phishing Targets Microsoft 365 Accounts Without Stealing Passwords.
ESET analysts are warning about a new type of phishing attack that has been used to target hundreds of organisations in just one month. Its strength lies in the fact that cybercriminals can gain access to Microsoft 365 accounts without stealing passwords or directing victims to fake login pages.
The victim signs in through a genuine Microsoft portal, often with two-factor authentication enabled, and unknowingly approves a login attempt from the attacker’s device.
EvilTokens operates as phishing-as-a-service, meaning it is a ready-made tool that criminals can purchase and deploy without advanced technical knowledge. The service is promoted through Telegram and has reportedly been used in attacks since at least February 2026.
It was quickly adopted by cybercriminals. In March 2026 alone, it was used in attacks targeting more than 340 organisations across several countries. Microsoft has also described an AI-assisted variant of the attack, in which device codes were generated dynamically and phishing lures were personalised to increase their effectiveness.
How the attack works
The mechanics of the attack are surprisingly simple. Cybercriminals often begin by checking in advance whether a target account is active. Microsoft observed such reconnaissance activity taking place as early as 10 to 15 days before the actual attack.
The victim then receives a message impersonating an invoice, a shared document, a calendar invitation or a request for access to SharePoint. The message typically includes a short instruction such as “Verify to view” or “Signature required”.
After clicking the link, the victim is shown a device code and redirected to Microsoft’s legitimate login page at microsoft.com/devicelogin. However, the code displayed to the victim actually belongs to the attacker’s session.
By entering it, the user is not logging in to their own account. Instead, they are authorising the attacker’s login attempt.
This can give the attacker access to corporate email, files, Microsoft Teams and cloud storage. From there, criminals may steal sensitive data or prepare a business email compromise, or BEC, attack using the compromised corporate mailbox.
“EvilTokens removes the warning signs that users have been taught to recognise for years. There is no suspicious domain with a typo and no fake login form, because the login page is genuine. From the victim’s perspective, the entire authentication process looks exactly as it should,” says Kamil Sadkowski, cybersecurity analyst at ESET.
“The attack also undermines the sense of security provided by two-factor authentication. This second layer of protection is more important than ever, but it will not work when the victim personally approves the wrong session. Criminals are not bypassing 2FA through a technical trick. They are persuading the victim to complete that step on their behalf.”
How to reduce the risk
Advice such as checking the website address or looking for spelling mistakes remains useful, but it does not protect against attacks that abuse legitimate login mechanisms.
For organisations, an important step is to restrict device code authentication where it is not needed, for example by using conditional access policies. Companies should also monitor unusual login activity and access attempts from unknown devices.
“Context is crucial in this case. Before approving any login attempt, users should check which application is requesting access and which account the request concerns. Being redirected to a genuine Microsoft website does not automatically mean that the request is safe,” says Kamil Sadkowski, cybersecurity analyst at ESET.
“Any unexpected request to enter a device code should be treated as suspicious and reported to the IT or security department.”
The growing use of phishing-as-a-service tools such as EvilTokens shows that cyberattacks are becoming easier to launch and harder to recognise. Technical safeguards remain essential, but employee awareness must increasingly focus not only on suspicious websites and fake domains, but also on understanding the context of every login request.





