# EvilTokens: A phishing attack that doesn't steal your password

DevFeed: [EvilTokens: A phishing attack that doesn't steal your password](<https://devfeed.tech/articles/eviltokens-a-phishing-attack-that-doesn-t-steal-your-password-8347.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/>)

Author: Christian Ali Bravo

Published: 2026-06-15T08:55:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [OAuth 2.0](<https://devfeed.tech/topics/oauth2.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [microsoft 365](<https://devfeed.tech/topics/microsoft-365.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [process](<https://devfeed.tech/tags/process.md>), [time](<https://devfeed.tech/tags/time.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

## AI overview

EvilTokens is a phishing-as-a-service kit that abuses Microsoft 365's OAuth 2.0 device authorization flow to compromise accounts without directly stealing passwords. Victims authenticate on Microsoft's genuine login page, unknowingly approving an attacker-controlled device; the resulting access and refresh tokens can enable account takeover and business email compromise.

## Source excerpt

A phishing kit subverting Microsoft's legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages