SECURITY ALERT · MICROSOFT 365
Microsoft 365 Device-Code Phishing: What Organizations Should Check After the EvilTokens Campaign
Microsoft's investigation into EvilTokens highlights how attackers can abuse legitimate device-code authentication to obtain tokens, access Microsoft 365 mailboxes and support business email compromise.
EXECUTIVE SUMMARY
A legitimate authentication flow is being turned against users.
Microsoft Threat Intelligence has detailed activity involving EvilTokens, a phishing-as-a-service platform that supports device-code phishing, token theft and business email compromise.
Microsoft reports that campaigns facilitated by EvilTokens compromised more than 12,000 inboxes across over 10,000 organizations worldwide.
The technique is particularly important because victims can be directed to a legitimate Microsoft authentication experience. The attacker does not necessarily need to steal the user's password directly; instead, the victim can unknowingly authorize a session initiated by the attacker.
HOW DEVICE-CODE PHISHING WORKS
The Microsoft sign-in page can be real. The request behind it is not.
Device-code authentication is a legitimate OAuth flow designed for devices that cannot easily provide a normal browser or keyboard-based sign-in experience.
In a legitimate scenario, a device displays a short code. The user opens a browser on another device, enters the code and completes authentication.
In a phishing scenario, the attacker starts the device-code flow and sends the resulting code to the victim through a deceptive message. If the victim enters that code and approves the authentication, the attacker-controlled session can receive access.
Attacker starts flow
A device-code authentication request is initiated.
Victim receives code
Social engineering convinces the user that the code is legitimate.
User authenticates
The victim enters the code into Microsoft's legitimate authentication flow.
Attacker gains session
The attacker can receive tokens associated with the authorized session.
EVILTOKENS CAMPAIGN
Phishing infrastructure built for scale.
According to Microsoft, EvilTokens developed into a widely used phishing-as-a-service platform after emerging in February 2026.
The platform provided prebuilt phishing templates, AI-assisted lure creation and infrastructure designed to support device-code phishing and token theft.
inboxes Microsoft says were compromised through campaigns facilitated by the platform.
organizations worldwide affected by those campaigns.
phishing themes observed by Microsoft, including invoices, RFPs and shared-file lures.
WHY THIS ATTACK MATTERS
The attack targets the authentication process rather than simply asking for a password.
Multifactor authentication remains an essential security control. However, Microsoft explains that device-code phishing can circumvent traditional MFA protections by separating the authentication event from the attacker-controlled session that initiated it.
This is why organizations need controls around authentication flows in addition to simply enabling MFA.
AFTER COMPROMISE
Mailbox access can become the starting point for further abuse.
Microsoft observed stolen tokens being used for email access and exfiltration. Attackers also created malicious inbox rules to conceal communications and support persistence.
EvilTokens also provided capabilities to analyze compromised mailbox content and perform Microsoft Graph reconnaissance, helping attackers understand organizational relationships and identify additional opportunities for business email compromise or lateral movement.
WHAT ORGANIZATIONS SHOULD CHECK
Start with visibility before enforcing a tenant-wide block.
Device-code flow may still be legitimately required by Teams devices, developer tools, administrative tools or other scenarios. Organizations should identify those dependencies before enforcing changes.
Use Microsoft Entra sign-in logs to identify where device-code authentication is currently being used and which users, applications and resources depend on it.
Determine whether Teams devices, Azure CLI, developer tools, administrative tools or legacy workflows genuinely require device-code authentication.
Microsoft recommends blocking device-code flow wherever possible using Conditional Access.
Where device-code authentication is required, scope exceptions to documented scenarios rather than broad user populations.
Investigate suspicious inbox-rule creation, unexpected mailbox access, unusual sign-ins and other indicators associated with business email compromise.
Continue strengthening MFA with phishing-resistant authentication methods such as passkeys or FIDO-based credentials where appropriate.
CONDITIONAL ACCESS
Test before enforcing.
Microsoft Entra Conditional Access can explicitly target device-code authentication flow. Microsoft recommends organizations get as close as practical to blocking device-code flow while maintaining narrowly controlled exceptions for legitimate requirements.
Before moving a new policy into enforcement, review existing usage and use report-only mode to understand potential impact.
IF COMPROMISE IS SUSPECTED
Token theft requires an identity and mailbox response.
Microsoft recommends following compromised-account response guidance, revoking refresh tokens and investigating mailbox activity when suspected device-code phishing is identified.
Microsoft also notes that existing access tokens may remain active for a period after standard session revocation. In an active compromise, temporary account disabling may therefore be considered as part of immediate containment.
Incident response should also examine suspicious inbox rules, malicious forwarding, unusual authentication activity, affected devices and evidence of further account or organizational compromise.
NOAVAXIS RECOMMENDATION
Treat device-code flow as an exception, not a default.
Organizations should first establish whether device-code authentication has a legitimate business requirement.
Where it is not needed, block it. Where it is required, document the dependency, restrict the exception, assign an owner and review it regularly.
MICROSOFT 365 IDENTITY SECURITY
Do you know where device-code authentication is being used?
NOAVAXIS can help review Microsoft Entra authentication activity, Conditional Access, device-code dependencies and identity security controls to identify unnecessary exposure and build a practical remediation plan.
Talk to NOAVAXIS