← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
New widespread EvilTokens kit: device code phishing as-a-service
EvilTokens is a new Phishing-as-a-Service offering a turnkey Microsoft device code phishing kit. It enables attackers to harvest access and refresh tokens, granting unauthorized access to victims' Microsoft accounts. The kit supports post-compromise operations, allowing data exfiltration from various Microsoft services. EvilTokens has been rapidly adopted by cybercriminals since March 2026, impacting organizations globally. The service provides advanced capabilities for account takeover, including token conversion to Primary Refresh Tokens and browser cookies for persistent access. Phishing campaigns using EvilTokens target employees in finance, HR, logistics, and sales, primarily for Business Email Compromise attacks.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | authdocspro.com | — | 2026-03-31 | |
| domain | backdoor-hub.com | — | 2026-03-31 | |
| domain | bumpgames.net | — | 2026-03-31 | |
| domain | carbatterygurgaon.com | — | 2026-03-31 | |
| domain | careldutoit-el.co.za | — | 2026-03-31 | |
| domain | eqfit.co.za | — | 2026-03-31 | |
| domain | eventcalender-schedule.com | — | 2026-03-31 | |
| domain | evobothub.org | — | 2026-03-31 | |
| domain | framebound.cloud | — | 2026-03-31 | |
| domain | infinitechai.org | — | 2026-03-31 | |
| domain | macmamo.com | — | 2026-03-31 | |
| domain | mirsanotolastik.com | — | 2026-03-31 | |
| domain | mirzanyapi.com | — | 2026-03-31 | |
| domain | newmobilepolojean.com | — | 2026-03-31 | |
| domain | notificationsmanagersec.com | — | 2026-03-31 | |
| domain | pelangiservice.com | — | 2026-03-31 | |
| domain | prcservis.com | — | 2026-03-31 | |
| domain | serenitygovsupplys.com | — | 2026-03-31 | |
| domain | smstltle.net | — | 2026-03-31 | |
| domain | suctwocesonesstory.com | — | 2026-03-31 | |
| domain | thesafarigarden.com | — | 2026-03-31 | |
| domain | topbuysella.com | — | 2026-03-31 | |
| domain | totalhomesafe.com | — | 2026-03-31 | |
| domain | xlkconsulting.co.za | — | 2026-03-31 | |
| domain | yankeepine.co | — | 2026-03-31 | |
| domain | youremplregroup.com | — | 2026-03-31 | |
| hostname | docusend.networkssolutionmail.com | — | 2026-03-31 | |
| hostname | internalmemorecord.bxwancheng.com | — | 2026-03-31 | |
| hostname | promanager.outboundciwidey.com | — | 2026-03-31 | |
| hostname | signaturerequired.thecoolcactus.com | — | 2026-03-31 | |
| hostname | statushelper.aguasomos.com | — | 2026-03-31 | |
| hostname | update.youcreadio.cfd | — | 2026-03-31 | |
| hostname | well.atlantaperlnatal.com | — | 2026-03-31 |