PULSE NAME
New widespread EvilTokens kit: device code phishing as-a-service
WHITE AlienVault 2026-03-31 Modified: 2026-03-31
33
IOCs
MEDIUM VOLUME
EvilTokens is a new Phishing-as-a-Service offering a turnkey Microsoft device code phishing kit. It enables attackers to harvest access and refresh tokens, granting unauthorized access to victims' Microsoft accounts. The kit supports post-compromise operations, allowing data exfiltration from various Microsoft services. EvilTokens has been rapidly adopted by cybercriminals since March 2026, impacting organizations globally. The service provides advanced capabilities for account takeover, including token conversion to Primary Refresh Tokens and browser cookies for persistent access. Phishing campaigns using EvilTokens target employees in finance, HR, logistics, and sales, primarily for Business Email Compromise attacks.
Indicators of Compromise (33)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain authdocspro.com 2026-03-31
domain backdoor-hub.com 2026-03-31
domain bumpgames.net 2026-03-31
domain carbatterygurgaon.com 2026-03-31
domain careldutoit-el.co.za 2026-03-31
domain eqfit.co.za 2026-03-31
domain eventcalender-schedule.com 2026-03-31
domain evobothub.org 2026-03-31
domain framebound.cloud 2026-03-31
domain infinitechai.org 2026-03-31
domain macmamo.com 2026-03-31
domain mirsanotolastik.com 2026-03-31
domain mirzanyapi.com 2026-03-31
domain newmobilepolojean.com 2026-03-31
domain notificationsmanagersec.com 2026-03-31
domain pelangiservice.com 2026-03-31
domain prcservis.com 2026-03-31
domain serenitygovsupplys.com 2026-03-31
domain smstltle.net 2026-03-31
domain suctwocesonesstory.com 2026-03-31
domain thesafarigarden.com 2026-03-31
domain topbuysella.com 2026-03-31
domain totalhomesafe.com 2026-03-31
domain xlkconsulting.co.za 2026-03-31
domain yankeepine.co 2026-03-31
domain youremplregroup.com 2026-03-31
hostname docusend.networkssolutionmail.com 2026-03-31
hostname internalmemorecord.bxwancheng.com 2026-03-31
hostname promanager.outboundciwidey.com 2026-03-31
hostname signaturerequired.thecoolcactus.com 2026-03-31
hostname statushelper.aguasomos.com 2026-03-31
hostname update.youcreadio.cfd 2026-03-31
hostname well.atlantaperlnatal.com 2026-03-31