Type
Campaign
Actors
Pub. date
April 7, 2026
Initial access
End-user compromise
Impact
Data exfiltration
Observed techniques
Targeted technologies
Status
Finalized
Last edited
Apr 29, 2026 12:14 PM
A phishing campaign has been reported leveraging the EvilTokens Phishing-as-a-Service platform to target O365 users. The attackers use device code phishing to bypass Multi-Factor Authentication (MFA), and they also utilize Railway to host their malicious infrastructure.
The campaign centers on Device Code Flow phishing. Unlike traditional phishing that steals passwords, this method tricks users into performing a "Device Login" for an application:
- Device Code Exploitation: The victim is prompted to enter a unique code on a legitimate Microsoft page (
microsoft.com/devicelogin). By doing so, the victim authorizes the attacker's "device" (the EvilTokens server) to access their account. - MFA Bypass: Since the victim completes the authentication on their own trusted device/browser, MFA is satisfied, and the attacker receives a Primary Refresh Token (PRT) or access token.
- Defense Evasion: Rather than relying on a fake login page, the attackers use legitimate Microsoft infrastructure for the authentication process itself, making it much harder for users to detect the fraud and for automated systems to flag the URL as malicious.