EvilTokens PhaaS Bypasses MFA to Hit 340 Microsoft 365 Organisations

A phishing-as-a-service platform called EvilTokens compromised over 340 Microsoft 365 organisations in five weeks by hijacking OAuth consent flows. This attack bypasses MFA without ever touching a password.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
Cybersecurity analyst reviewing a suspicious Microsoft 365 authentication prompt on a corporate workstation

Cybersecurity analyst reviewing a suspicious Microsoft 365 authentication prompt on a corporate workstation

A phishing-as-a-service platform has compromised more than 340 Microsoft 365 organisations across five countries in under five weeks, and it does so without ever asking for a password or triggering a standard MFA alert.

The platform, named EvilTokens, went live in February 2026. It exploits the OAuth device authorisation flow, a mechanism designed for devices without a browser. Victims receive a message asking them to enter a short code at a legitimate Microsoft sign-in page and complete their normal MFA challenge. The moment they do, the platform's operator receives a valid OAuth refresh token scoped to the victim's mailbox, OneDrive, calendar, and contacts. The token's lifespan is governed by the organisation's own policy, meaning access can persist for weeks or months.

The operator gains all of this with no password, no suspicious sign-in event, and no MFA prompt. Conventional credential-phishing defences do not examine the OAuth consent layer at all, leaving security teams effectively blind.

Why this matters for GCC enterprises

This is not a Microsoft vulnerability. It is a structural abuse of a trusted industry standard, and it works against any organisation running Microsoft 365, including the large number of UAE enterprises and regional financial institutions that have migrated core operations to the platform. Organisations in Saudi Arabia subject to NCA compliance requirements around identity governance are equally exposed, given that the attack produces no artefacts that standard log monitoring would flag as a breach.

What the token enables

Once EvilTokens delivers a refresh token, access survives password resets. Observed post-exploitation activity includes business email compromise (BEC) fraud, exfiltration of sensitive documents, lateral movement through shared Teams and calendar data, and in several cases, the stolen access was subsequently resold to ransomware affiliates. The attack requires nothing beyond one uninformed click from the victim.

What security teams should do

Conditional access policies in Microsoft Entra ID can block device code flow authentication for users not on managed, compliant devices. Where that is not immediately feasible, a tenant-wide audit of OAuth grants to identify authorisations tied to unrecognised applications or unfamiliar device flows is the first step.

Standard phishing simulation programmes do not cover this vector. Most enterprise users across the region have never been trained to question an OAuth consent screen. That gap is precisely what EvilTokens exploits.

The UAE Cyber Security Council and regional regulators have consistently highlighted identity security as a priority area for 2026. EvilTokens provides a concrete, current demonstration of why that guidance is operationally urgent for every enterprise running cloud productivity infrastructure in the region.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Identity Security GCCCloud Security MENAMicrosoft 365 Threat IntelligenceEnterprise Threat LandscapePhishing Intelligence 2026