EvilTokens: Phishing Service Uses AI to Target Next Victims
A phishing service called EvilTokens has been discovered to not only steal Microsoft Sessions but also use AI to help attackers choose their next targets. The service uses a real Microsoft sign-in process, where a device code is created and the user is directed to the authentic login site to approve it.
Unlike conventional credential-stealing kits, EvilTokens uses OAuth device code phishing, which leaves victims at a genuine destination. This makes it harder for users to identify suspicious activity.
The service has been documented in February 2026 and is sold mainly through Telegram. It offers session capture with post-compromise analysis, making it useful even for affiliates with limited knowledge of financial fraud.
EvilTokens searches mailboxes for invoices, payment requests, pending transactions, and past exchanges to identify suppliers, decision-makers, and people who approve payments. The AI then summarizes the email data and creates messages shaped around real business relationships, allowing attackers to target known, trusted contacts.