Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

EvilTokens abuses a legitimate Microsoft sign-in feature: an attacker starts a device authorization request, then persuades a victim to approve it by entering the attacker’s code on Microsoft’s real sign-in page. The victim may complete authentication—including multifactor authentication—successfully, but the resulting authorized session belongs to the attacker. The key defense is to block device-code sign-in where it is not needed and tightly restrict any business exception.

What device-code phishing is—and why the real sign-in page can be part of it

The OAuth 2.0 Device Authorization Grant is a legitimate way for a device with limited browser or input capability to obtain authorization. The device displays a user code and verification address. The user opens that address on another device, signs in, and approves the request; meanwhile, the original client polls the authorization server for the result. RFC 8628 describes the design: “Since the protocol supports clients that can’t receive incoming requests, clients poll the authorization server repeatedly until the end user completes the approval process.”

That separation between the requesting client and the device used to approve it is useful for legitimate devices, but it creates an opportunity for abuse. In a phishing attack, the attacker is the requesting client. The attacker gives the victim a code and directs them to the genuine Microsoft device sign-in page. If the victim enters the code and approves the prompt, Microsoft authorizes the attacker’s waiting session.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This differs from the familiar fake-login-page attack: the victim may never enter a password on a counterfeit site. The real Microsoft page can be involved because it is the approval step the attacker needs. Microsoft’s device-login page warns, “Do not enter codes from sources you don’t trust.” Treat an unexpected code request as suspicious even when the URL is genuine.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How an EvilTokens attack proceeds

  1. The attacker starts a device flow. EvilTokens generates a live device code and verification address for an authorization request.
  2. The attacker delivers a lure. A message or attachment invites the target to open a file, review a shared document, sign paperwork, hear voicemail, or address another plausible business request. Microsoft has described malicious URLs, PDFs, and HTML files, as well as multi-stage redirects and serverless hosting. Sekoia’s March 30, 2026 technical report also describes delivery formats including XLSX, SVG, and DOCX.
  3. The victim enters the attacker’s code. The lure sends the victim to the official device-login portal. The victim signs in and approves the request, potentially completing MFA as part of the legitimate authentication process.
  4. The attacker retrieves the authorized session. While the victim completes approval, the attacker’s client polls for completion and can obtain tokens for the authorized account.
  5. The attacker uses the access and seeks persistence. The compromised account can be examined for valuable conversations and used to target colleagues or external contacts. Attackers may also create inbox rules or register devices to make access harder to spot or remove.

MFA is not inherently useless here: the problem is that the victim is being induced to authenticate and approve the attacker’s request. The approval is real, but its purpose is misrepresented to the user.

What Microsoft and Sekoia reported about EvilTokens

Microsoft Threat Intelligence says the EvilTokens platform appeared in February 2026 and attributes its development and support to Storm-2992. Microsoft describes prebuilt phishing templates and landing pages, AI assistance to tailor lures, and post-compromise assistance to review mailbox activity and identify valuable targets.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft reported more than 12,000 inboxes compromised in over 10,000 organizations worldwide. Those are Microsoft’s reported observations in 2026, not a universal count of all device-code phishing or a complete measure of the platform’s reach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sekoia’s independent tracking and SOC telemetry reported more than 1,000 domains hosting EvilTokens pages. Separately, as of March 23, 2026, Sekoia reported more than 900 confirmed results from a query for the X-Antibot-Token header. These figures measure different things from Microsoft’s inbox and organization counts; they should not be added together or treated as equivalent prevalence estimates.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Microsoft described lures themed around invoices, requests for proposals, shared files, document signing, cloud services, voicemail, and eFax. Its reported victim activity was highest in the United States, Canada, the United Kingdom, Australia, India, and France, with affected industries including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Sekoia’s March 2026 report observed campaign activity across the Americas, Europe, the Middle East, Asia, and Oceania. These are observations from the respective publishers, not a complete census of victims or regions.

What attackers may do after approval

Read mail and choose valuable targets

Microsoft reports mailbox analysis to find financial, executive, or administrative targets. Attackers can use information in a compromised account to craft credible messages to colleagues and outside contacts, extending the campaign through trusted conversations.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Map the organization and maintain access

Reported post-compromise activity includes Microsoft Graph reconnaissance to understand organizational structure and permissions, malicious inbox rules that conceal or redirect communications, and anomalous device registration that may help preserve access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reach other Microsoft 365 resources

Sekoia’s technical analysis describes attempts to exchange captured refresh tokens for a Primary Refresh Token and additional resource tokens, including for Outlook, Microsoft Graph, Azure, and SharePoint. Its analysis discusses possible access to Exchange Online mail, SharePoint and OneDrive documents, and Teams conversation history. These are capabilities documented in the kit’s analysis; they do not establish that every capability was used in every incident.

Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which controls administrators should prioritize

Block the flow where it is not required

Microsoft’s first recommendation is to block device-code flow wherever possible. If an organization needs the flow for Teams devices, Microsoft advises limiting the exception to the specific Teams device resource accounts and accounting for the Device Registration Service in Conditional Access configuration. Avoid a broad exception that makes the flow available to unrelated users or accounts.

Make approval requests understandable to users

Train users to question unexpected instructions to enter a sign-in code, even if the page is a genuine Microsoft page. Sign-in prompts should make clear which application or request the user is authorizing. Users should not approve a request simply because a familiar provider is displaying it.

Strengthen filtering and detection

Microsoft recommends anti-phishing policies and Safe Links. It says Safe Links together with Entra ID Protection can raise high-confidence device-code phishing alerts. Administrators should monitor for suspicious inbox-rule creation, unusual device registration, device-code authentication, token exchange, and anomalous Graph activity; Microsoft also identifies related Defender XDR and Defender for Identity detections.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use phishing-resistant authentication as one layer

Microsoft recommends phishing-resistant methods such as FIDO tokens or Authenticator with passkey. These belong in a layered identity strategy; Microsoft does not present them as a replacement for controlling device-code flow. The cited reporting does not establish that any particular hardware security key, by itself, prevents this attack.

What to do if an account may have been compromised

  1. Contain the identity. Follow the organization’s compromised-account response process. Microsoft advises considering temporary account disabling for immediate containment in the circumstances it describes.
  2. Revoke refresh tokens and force reauthentication. Revoke refresh tokens and consider requiring the user to authenticate again. Microsoft cautions that existing access tokens may remain active for up to an hour after standard session revocation, so revocation alone may not immediately end every active session.
  3. Investigate activity beyond sign-in. Review mailbox rules and sent mail, device registrations, device-code authentication, token exchanges, Graph activity, and access to relevant Microsoft 365 resources. Look for follow-on messages sent to coworkers or external contacts.
  4. Remove persistence and address affected recipients. Remove unauthorized rules or device registrations, assess the scope of data access, and warn recipients who may have received attacker messages from the compromised account.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.