Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

EvilTokens abused Microsoft’s legitimate device-code sign-in flow to take over organizational accounts without asking victims to give the phisher their passwords. A victim could visit Microsoft’s genuine sign-in page, enter a code, and still authorize a session started by an attacker. Microsoft reported that the EvilTokens service was disrupted on September 22, 2026, but the underlying technique remains a risk wherever device-code sign-in is available and insufficiently controlled.

What is device-code phishing?

Device-code authentication is a legitimate OAuth sign-in method for devices with limited interfaces, such as smart TVs, printers, Teams devices, and conferencing equipment. The device displays a short code; its user enters that code on a different device, usually in a browser, and completes sign-in there.

In device-code phishing, the attacker starts the sign-in request and then persuades a victim to complete it. The victim’s approval binds the account to the attacker’s pending request—not necessarily to a device or activity the victim intended to authorize. Because the person may use Microsoft’s real device-login site and never disclose a password to the phisher, advice focused only on spotting fake login pages or protecting passwords does not address this attack.

The flow also changes what multi-factor authentication (MFA) protects. A victim may complete the normal authentication steps, including MFA, while the attacker receives the resulting authenticated session. Microsoft describes the decoupled flow as a way attackers can circumvent traditional MFA protections; MFA is not a guarantee against a victim approving an attacker-initiated sign-in.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How did the EvilTokens attack work?

Microsoft’s April 6, 2026 campaign analysis describes a phishing page that could obtain a live device code near the time a victim arrived, rather than relying on a code embedded in an email well in advance. Microsoft says a device code is valid for 15 minutes. Generating it near the victim’s visit avoids the risk that it will expire before the victim acts. The attacker’s service checked the sign-in request’s status while the victim completed Microsoft’s ordinary flow.

This timing is important for defense: a genuine Microsoft sign-in page does not establish that the sign-in was initiated by the person using it. The meaningful question is whether the device-code request and resulting session match an expected user, app, device, and business purpose.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What Microsoft reported about the service

Microsoft Threat Intelligence reported on September 22, 2026, that EvilTokens was a phishing-as-a-service platform associated with threat actor Storm-2992. It used AI-assisted phishing infrastructure as well as device-code authentication abuse. Microsoft said campaigns affected more than 12,000 inboxes in over 10,000 organizations worldwide. The sectors it named included wholesale distribution, construction, financial services, real estate, higher education, and healthcare; its highest observed victim concentrations were in the United States, Canada, the United Kingdom, Australia, India, and France.

Microsoft’s Digital Crimes Unit and partners facilitated a coordinated disruption of infrastructure used to operate EvilTokens. That is Microsoft’s reported status for the service as of September 22, 2026; it does not mean device-code phishing as a technique has ended.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What can an attacker do after taking over an account?

Microsoft reported that EvilTokens users could access victims’ email and refresh captured tokens. The service could scan inboxes for keywords and use AI assistants to summarize or translate messages, identify financial conversations and organizational roles, and find trusted relationships or potential impersonation targets.

Reported post-compromise activity included mailbox exfiltration, malicious inbox rules intended to conceal communications, Microsoft Graph reconnaissance, and, in some cases, registering devices to establish persistence. Microsoft’s April campaign analysis describes examples in which some persistence actions occurred within minutes while other activity was delayed for hours. Those are observed examples, not a guaranteed sequence or timing.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What should Entra administrators investigate?

Look for device-code sign-ins that are unexpected for the user, application, resource, device context, or location, especially when followed by suspicious token activity or mailbox changes. Microsoft’s September 2026 EvilTokens article maps relevant behaviors to Defender for Identity and Defender XDR detections and hunting guidance. Treat an alert as a lead to investigate, not proof by itself that EvilTokens was involved.

  • Device-code authentication followed by anomalous token exchange or refresh activity.
  • Unfamiliar device registrations, particularly when they follow an unexpected sign-in.
  • Unexpected Microsoft Graph activity, mailbox access, or mailbox exfiltration.
  • Suspicious inbox rules, forwarding, or other changes that could hide or redirect messages.
  • Unexpected device-code use by privileged users, emergency access accounts, unfamiliar apps, or from unusual locations.

Microsoft Entra sign-in logs distinguish Authentication protocol = Device code flow from Original transfer method = Device code flow. The first can identify a sign-in using the flow; the second can help identify later sign-ins or token refreshes linked to an earlier device-code session. Review both when investigating related activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can you block device-code flow without breaking legitimate work?

Microsoft’s official guidance states: “Microsoft recommends blocking device code flow wherever possible.” A tenant-wide block may disrupt legitimate dependencies, so first establish which users, apps, resources, locations, and devices actually rely on it. Microsoft identifies Azure CLI, developer tools, admin tools, and legacy command-line workflows as possible non-Teams dependencies.

Option When it fits What to validate
Block device-code flow Use where inventory shows no necessary dependency, or after dependencies have migrated. Check sign-in logs and Conditional Access report-only results for expected effects before enforcement.
Migrate the dependency Prefer this when a tool or workflow can use browser-based or brokered sign-in, a managed identity, or workload identity federation instead. Confirm the replacement works for the app and its users, then document the change and reassess the need for an exception.
Keep a narrowly scoped exception Use only when a documented business dependency still requires device-code flow. For Teams device scenarios, Microsoft’s guidance recommends a narrowly scoped exception for the Teams device resource account; it also calls out excluding Device Registration Service where the policy requires it. Validate the policy and sign-in results, and avoid broad user exclusions.

Microsoft’s Teams-specific Conditional Access guidance recommends testing with report-only policy results and reviewing sign-in logs. Keep an exception tied to a known business owner and the required app or resource, location, and device context. Revisit it as dependencies change; do not treat an exception as a permanent substitute for migration or monitoring.

What should you do if you suspect a takeover?

Follow your organization’s incident-response process and investigate the affected identity, sessions, mailbox, and devices. Revoke affected sessions and tokens as part of containment; Microsoft’s public EvilTokens explainer warns that access could persist after a password reset if associated sessions and tokens were not also revoked.

  • Review mailbox rules, forwarding, and affected mailbox content for concealment, redirection, or exposure.
  • Check device registrations and related OAuth, token, and Microsoft Graph activity.
  • Investigate related accounts and activity, including any signs of impersonation or access to financial conversations.
  • Use Microsoft’s current Defender guidance to investigate and remediate the observed activity.

Can Token Protection stop device-code phishing?

Token Protection is one part of Microsoft’s broader guidance for reducing attack surface, detecting and mitigating token theft, and protecting against token replay. Microsoft says the feature can cryptographically bind supported refresh tokens to a device, but coverage is limited to supported applications and platforms and applies only to the user signed in on the device. Check current support for the specific app, platform, and identity scenario before relying on it. It complements restricting unnecessary device-code flow and monitoring; it does not replace either control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.