Skip to content
EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics

EvilTokens Phishing Kit Exploits Microsoft 365 with AI-Driven BEC Tactics

First seen 1 Jul 2026, 10:45 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 2, 2026 at 10:13 UTC

In March 2026, the EvilTokens phishing kit emerged as a significant threat, allowing cybercriminals to bypass multi-factor authentication (MFA) and compromise Microsoft 365 accounts. This Phishing-as-a-Service (PhaaS) platform utilizes Microsoft's OAuth 2.0 Device Authorization Grant to capture victim tokens, enabling Business Email Compromise (BEC) attacks. The platform has rapidly gained traction, with Microsoft reporting hundreds of organizations compromised daily. Cisco Talos identified an affiliate panel named ARToken, which enhances EvilTokens' capabilities by incorporating AI for personalized lures and automated post-compromise actions. The phishing campaigns have increased by 1,380% compared to the previous year, with targeted emails leveraging real vendor relationships to deceive victims. The attack method involves sending emails that appear legitimate but redirect to attacker-controlled Microsoft 365 workspaces. Current assessments indicate that EvilTokens and its affiliates are continuously evolving their tactics, posing a serious threat to organizations using Microsoft 365.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 89d ago How this analysis works

Timeline

2026-03-25
EvilTokens first reported
Sekoia published findings on EvilTokens, detailing its phishing capabilities targeting Microsoft 365.
Sekoia
2026-04
Microsoft confirms campaign scale
Microsoft reported that EvilTokens was compromising hundreds of organizations daily, with increased attack success rates.
The Register
2026-04-20
Talos identifies ARToken panel
Cisco Talos discovered the ARToken panel, linked to EvilTokens, enhancing phishing operations with AI.
Talos Intelligence
2026-07-01
EvilTokens attacks escalate
Cisco Talos reported a dramatic increase in EvilTokens phishing attacks, indicating a more sophisticated operational model.
Cyberscoop

More articles in this cluster (44)

Following this threat?

Track Icarus, ClickFix and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed