What is device code phishing? EvilTokens platform and operations EvilTokens phishing emails Mitigation and protection guidance Microsoft Defender XDR detections Hunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets.

Read the full article at Microsoft Security →