What is device code phishing? EvilTokens platform and operations EvilTokens phishing emails Mitigation and protection guidance Microsoft Defender XDR detections Hunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised inboxes to identify high-value targets.
Unmasking EvilTokens: Getting to the root of device code phishing
About this summary. This is a short, independently written summary of an article first published by Microsoft Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/

Source attribution: headline and facts are from Microsoft Security (microsoft.com). Summary method: excerpt of the source description. See our source attribution policy.






