EvilTokens Phishing Kit Is Far Nastier Than Anyone Realised
EvilTokens, the device-code phishing kit designed to bypass multi-factor authentication and silently hijack Microsoft 365 sessions, just got a lot more worrying. Cisco Talos researchers have published new findings showing the operation is more sophisticated, more evasive, and considerably more fully-featured than earlier analysis suggested.
The Talos report, published Wednesday, fills in a gap that previous coverage left open: how the phishing lure actually lands in someone's inbox. Researchers recovered two near-identical emails sent four minutes apart on April 20th this year, and what they found was not the crude spray-and-pray approach you might expect.
The attack exploited a genuine vendor relationship between a US life-sciences company and a legitimate plumbing and fire-protection contractor. The lure was a fake outstanding invoice notice, crafted to look like it came from the real contractor. The sender domain was the actual contractor's domain. The visible link in the body text appeared to point to the vendor's genuine SharePoint tenant. Classic trust abuse, executed with some care.
The catch, obviously, is that none of it holds up under scrutiny. The reply-to address redirected to an unrelated domain, and the actual hyperlink pointed to a copycat SharePoint tenant under an attacker-controlled Microsoft 365 workspace. But because the destination URL still resolves to a legitimate sharepoint.com host, it is much harder for email security tools to flag it.
Talos also uncovered a phishing-as-a-service operator panel called ARToken, which appears to be a customer of the EvilTokens platform. The two share infrastructure, API contracts, and operational patterns. EvilTokens was first documented by French firm Sekoia in March. By April, Microsoft was saying device-code phishing campaigns were hitting hundreds of organisations every single day, with ten to fifteen distinct campaigns launching every 24 hours.
The evasion capabilities Talos found go beyond what earlier researchers documented. The platform's anti-analysis measures are, in their words, notably more sophisticated.
More alarming is what ARToken offers once access is established. This is not just a token-theft kit. The platform includes a comprehensive post-exploitation suite: full Outlook inbox read access, the ability to send emails as the victim, inbox rule creation for message forwarding or deletion, and keyword monitoring across all compromised accounts. It handles token management and persistence too.
As Talos security research engineer Michael Kelley put it plainly, this is not a simple device-code phishing kit. It is a complete business email compromise operations environment. Which is precisely the kind of thing you do not want circulating as a service.