Skip to content
Back to Guavy Wire
Stocks

EvilTokens: Phishing Service Uses AI to Target Next Victims

Instruments
MSFT
Share

A phishing service called EvilTokens has been discovered to not only steal Microsoft Sessions but also use AI to help attackers choose their next targets. The service uses a real Microsoft sign-in process, where a device code is created and the user is directed to the authentic login site to approve it.

Unlike conventional credential-stealing kits, EvilTokens uses OAuth device code phishing, which leaves victims at a genuine destination. This makes it harder for users to identify suspicious activity.

The service has been documented in February 2026 and is sold mainly through Telegram. It offers session capture with post-compromise analysis, making it useful even for affiliates with limited knowledge of financial fraud.

EvilTokens searches mailboxes for invoices, payment requests, pending transactions, and past exchanges to identify suppliers, decision-makers, and people who approve payments. The AI then summarizes the email data and creates messages shaped around real business relationships, allowing attackers to target known, trusted contacts.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc