Executive Summary
In early 2026, the EvilTokens phishing-as-a-service (PhaaS) platform emerged, exploiting the OAuth 2.0 Device Authorization Grant to compromise Microsoft 365 accounts. This sophisticated campaign utilized AI to generate personalized phishing lures, leading to a 1,380% increase in device code phishing attacks between July–December 2025 and January–April 2026. Attackers bypassed multi-factor authentication (MFA) by redirecting legitimate authentication flows, granting them persistent access to corporate email, SharePoint, and OneDrive services. The campaign targeted hundreds of organizations daily, affecting sectors globally. (huntress.com)
The EvilTokens operation underscores a significant evolution in phishing tactics, leveraging AI to automate and personalize attacks at scale. This trend highlights the urgent need for organizations to reassess and strengthen their security postures, particularly concerning identity and access management, to mitigate the risks posed by increasingly sophisticated phishing campaigns. (securityboulevard.com)
Why This Matters Now
The rapid escalation of AI-driven phishing campaigns like EvilTokens demonstrates the evolving threat landscape, where traditional security measures, including MFA, are being circumvented. Organizations must urgently adopt advanced security strategies to protect against these sophisticated attacks.
Attack Path Analysis
The EvilTokens campaign initiates with AI-generated phishing emails containing device codes, leading victims to authenticate on legitimate Microsoft pages. Upon authentication, attackers gain persistent access to Microsoft 365 services without triggering MFA alerts. They then move laterally within the cloud environment, accessing additional resources. Command and control are maintained through the hijacked sessions, allowing continuous interaction with compromised accounts. Sensitive data is exfiltrated from services like Outlook and OneDrive. The impact includes unauthorized access to corporate communications and potential data breaches.
Kill Chain Progression
Initial Compromise
Description
Attackers send AI-generated phishing emails containing device codes, leading victims to authenticate on legitimate Microsoft pages.
MITRE ATT&CK® Techniques
Spearphishing Link
Spearphishing Link
Malicious Link
Valid Accounts
Password Guessing
Credential Stuffing
Web Protocols
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Protect all systems and networks from malicious software
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Ghost phishing bypasses traditional email security, threatening Microsoft 365 access and sensitive financial data with encrypted malicious payloads that decrypt in browsers.
Health Care / Life Sciences
EvilTokens campaign exploits email security blind spots, risking patient data exfiltration through hidden encrypted phishing pages targeting healthcare Microsoft 365 environments.
Government Administration
Decrypting phishing attacks evade URL checks, compromising government Microsoft 365 systems and sensitive administrative data through browser-based payload activation techniques.
Professional Training
Educational institutions face Microsoft 365 compromise risks from ghost phishing campaigns that hide malicious content until browser decryption exposes credential theft.
Sources
- New Ghost Phishing Wave Is Breaking Traditional Email Securityhttps://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.htmlVerified
- EvilTokens and the Rise of AI-Powered Phishinghttps://www.huntress.com/resources/eviltokens-ai-powered-phishing-reportVerified
- ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the EvilTokens campaign as it could likely limit attackers' ability to move laterally and exfiltrate data by enforcing strict workload segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could potentially limit the attacker's ability to exploit compromised credentials by enforcing strict identity-aware policies.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to escalate privileges by enforcing strict access controls based on workload identity.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely limit lateral movement by enforcing strict segmentation and monitoring of inter-workload communications.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely limit the attacker's ability to maintain command and control by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit data exfiltration by controlling and monitoring outbound traffic.
Aviatrix CNSF could likely reduce the overall impact of such attacks by limiting unauthorized access and containing potential data breaches through strict segmentation and access controls.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- Collaboration Platforms
- Cloud Storage
Estimated downtime: 7 days
Estimated loss: $500,000
Unauthorized access to corporate emails, confidential documents, and sensitive client information stored in Microsoft 365 services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within cloud environments.
- • Enhance Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud services.
- • Deploy Threat Detection & Anomaly Response systems to identify and mitigate unauthorized access.
- • Regularly review and update access controls and authentication mechanisms to prevent unauthorized access.



