EvilTokens device-code toolkit: Quite shady, more wicked than we realized

Revealing the New Villain in Technology: EvilTokens’ Deceptive Operations

EvilTokens, the clever device-code phishing toolkit allowing criminals to bypass multi-factor authentication (MFA) and infiltrate Microsoft 365 apps as unsuspecting users, is proving to be even more dubious than anticipated. Cisco Talos’ incident responders exposed details this Wednesday on how these deceptive emails reach your inbox, showcasing new strategies and a “more advanced evasion technique” compared to previous findings.

The ARToken Discovery

Talos discovered a phishing-as-a-service (PhaaS) control panel named “ARToken,” which appears to be a supporter of EvilTokens. As per security research engineer Michael Kelley, this phishing operation shares infrastructure, API agreements, and operational methods with the EvilTokens system. EvilTokens was initially detected by French cybersecurity company Sekoia in March, with Microsoft reporting by April that these phishing efforts were impacting hundreds of organizations each day. “Since March 15, 2026, we’ve observed 10 to 15 different campaigns emerging every 24 hours,” stated Microsoft VP of security research Tanmay Ganacharya to GadgetLad at that time. “Each campaign is substantial, targeting hundreds of organizations with highly varied and distinct payloads, complicating pattern-based detection significantly.”

The Deceptive Inbox Intrusion

While previous discussions surrounding EvilTokens have focused on its panel and phishing toolkit, “what is missing is the methodology of how an ARToken bait actually infiltrates an inbox,” Kelley remarked this Wednesday. Talos intercepted two nearly identical emails dispatched about four minutes apart on April 20, 2026, initiating the sequence. The deception is focused rather than random. In particular, the fraudulent email took advantage of a legitimate vendor relationship between a US life-sciences firm and an actual plumbing and fire-protection contractor. The email tempts with the notion of overdue invoices, asserting “the following invoices seem to remain unsettled,” while the “from” header showcases the contractor’s genuine domain. Conversely, the reply-to redirects to an arbitrary domain. Even the visible anchor text in the email content appears to be from the vendor’s legitimate SharePoint tenant, as informed. The actual href, however, leads to a near-identical counterfeit tenant under a different, attacker-controlled Microsoft 365 workspace. Nonetheless, as the destination remains a legitimate sharepoint.com host, the email is less likely to be perceived as suspicious.

The Intricate Web of ARToken

In their investigation into the ARToken phishing framework, Cisco revealed links to EvilTokens – including a corresponding API agreement to the one Sekoia first captured and akin deployment and operational models – along with “notably more refined” anti-analysis and evasion techniques. ARToken’s panel also disclosed a thorough post-exploitation toolkit that provides token management and persistence strategies, along with a built-in business email compromise (BEC) tool that grants full access to the victim’s Microsoft Outlook inbox, capabilities to send emails as the victim, creation of inbox rules for message forwarding and deletion, and keyword-based surveillance across all compromised accounts. “These functionalities indicate that the platform is more sophisticated than merely a basic device code phishing toolkit – it’s a comprehensive BEC operations environment,” Kelley noted.

Conclusion: Technology’s Little Underhanded Secret

EvilTokens is more elusive than a slick bar of soap in the shower. It’s no longer just about phishing kits – it’s a complete spectacle of mayhem in the realm of cybersecurity. Always stay vigilant and ensure your security software is up to date, everyone! For further details, visit gadgetlad.co.uk.