EvilTokens ramps up device code phishing targeting Microsoft 365 users

2026-03-31T14:51:49Z22f8674e9dd3496b6128ec31df0d411c364c3a332526cb62a39d074bb5b2ce0c
AxiosBitdefender','internal-attack-surface-assessment','Android-de…ClickFixEvilTokensFoxitMFA-fatigueMicrosoft-365PDF-securityRATSANS-surveyUranium-FinanceWindows-11backdoorconsolecrypto-jsdevice-code-phishingdroppersembedded-JavaScriptidentity-compromisemacOSnpmphishingsmart-contract-exploitsupply-chainterminal-warning

What happened

This feed highlights multiple active risks and defensive measures: a surge in device-code phishing against Microsoft 365 attributed to EvilTokens — a phishing toolkit offered as-a-service via Telegram that captures access/refresh tokens; a high-profile npm supply-chain compromise (trojanized crypto-js and backdoored Axios packages) that delivered droppers and remote access trojans; criminal charges in a $50M+ Uranium Finance smart-contract exploitation; and a SANS identity survey showing identity compromises and MFA fatigue. Defensive developments include Foxit’s PDF Action Inspector for JavaS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
22f8674e9dd3496b6128ec31df0d411c364c3a332526cb62a39d074bb5b2ce0c
Enrichment time
2026-03-31T14:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · EvilTokens ramps up device code phishing targeting Microsoft 365 users · Baitaphish