EvilTokens Leverages AI to Enhance Phishing and Business Email Compromise Scams
The EvilTokens service uses AI to analyze stolen Microsoft 365 session data, identifying key contacts and financial flows to craft highly convincing BEC scams.

The threat service known as EvilTokens is elevating phishing attacks by not only stealing Microsoft 365 session access but also employing artificial intelligence to analyze compromised mailbox data. This allows attackers to identify crucial contacts, payment patterns, and communication styles within an organization, enabling them to construct highly convincing business email compromise (BEC) scams.
EvilTokens operates by using a legitimate Microsoft OAuth device code phishing process. Victims are directed to a controlled page where a device code is generated, and then to Microsoft's authentic login site to approve it. This method bypasses traditional multi-factor authentication (MFA) by having the user approve the attacker's session on a genuine Microsoft page, leading to the issuance of session tokens to the criminal.
First documented in February 2026 and primarily sold via Telegram, EvilTokens offers a comprehensive solution for affiliates, even those with limited experience in financial fraud. Its effectiveness is demonstrated by its rapid adoption, with one 16-day period affecting 344 organizations across five countries, and other research indicating over 1,000 infrastructure-related search results and 66 email attachments leading to EvilTokens phishing pages.
The core innovation of EvilTokens lies in its post-compromise analysis. After gaining session access, the service scans mailboxes for invoices, payment requests, pending transactions, and past correspondence. It then identifies key figures such as suppliers, decision-makers, and payment approvers, while also mapping the organization's typical communication language and approval workflows.
This gathered intelligence is summarized by the platform's AI, which then generates tailored messages that mimic real business relationships. Attackers can leverage this information to target known, trusted contacts with fake invoices or urgent payment requests, significantly increasing the believability and success rate of their scams. This approach reduces the need for attackers to rely on generic templates or guesswork.
EvilTokens' capabilities accelerate the fraud process and personalize it by using details from authentic conversations. This lowers the barrier to entry for conducting BEC attacks and intensifies pressure on finance teams. The service effectively combines access, reconnaissance, and impersonation into a single subscription, reframing the risk of a stolen token from mere email access to a tool for selecting and preparing the next victim.
To combat this evolving threat, organizations are advised to restrict device-code authentication to essential uses or disable it where unnecessary. Security teams should monitor for unusual device-code grants, unfamiliar devices, new token issuances, and suspicious consent activities. Shorter token lifetimes and prompt session revocation can also mitigate the impact of successful approvals.
Users play a critical role by understanding that a legitimate login page does not guarantee the safety of a request. They must treat unexpected codes, approval prompts, and verification requests as suspicious and report them immediately. Furthermore, defenders should monitor for post-successful sign-in activities such as extensive mailbox searches, the creation of new inbox rules, token reuse, unauthorized access to cloud data, and messages sent on behalf of the user, as the OAuth device code phishing trend necessitates detection beyond the initial email.