EvilTokens: device code phishing kit more dangerous than ever

Discover how EvilTokens and ARToken bypass MFA and compromise Microsoft 365 accounts with evasion and BEC techniques.

jueves, 2 de julio de 2026 • 2 min read • Q2BSTUDIO Team

EvilTokens and ARToken: advanced evasion and BEC tools

The digital threat landscape continues to evolve alarmingly, and one of the most recent and sophisticated examples is EvilTokens, a device code phishing kit that has managed to bypass multi-factor authentication (MFA) systems and compromise business environments with worrying efficiency. Although initially documented as just another tool within the phishing-as-a-service (PhaaS) ecosystem, subsequent research has revealed much more advanced capabilities, such as integration with control panels enabling post-exploitation management, session token theft, and execution of large-scale business email compromise (BEC) campaigns. This type of attack not only jeopardizes Microsoft 365 security but also demonstrates how cybercriminals refine their techniques to avoid detection and perpetuate unauthorized access.

In a scenario where cybersecurity becomes a fundamental pillar for any organization, having robust technical defenses is no longer optional but necessary. At Q2BSTUDIO, we understand that protection must span from the infrastructure layer to intelligence applied to anomaly detection. Therefore, we offer AWS and Azure cloud services with secure configurations, continuous monitoring, and conditional access policies that make it difficult for tools like EvilTokens to exploit vulnerabilities in the authentication flow. Additionally, we combine these capabilities with business intelligence services that analyze access patterns and user behavior, enabling the identification of suspicious deviations before damage materializes.

EvilTokens' sophistication lies in its ability to impersonate legitimate business relationships, such as sending pending invoices from a real supplier domain, but redirecting the user to a SharePoint tenant controlled by the attacker. This type of social engineering, combined with the use of device codes, means even trained employees can fall into the trap. To mitigate these risks, it is essential to implement custom applications that integrate additional verification mechanisms, such as geographic context validation or known devices. At Q2BSTUDIO, we develop custom software that strengthens the security posture, including adaptive authentication modules and real-time phishing detection.

Artificial intelligence also plays a crucial role in defending against advanced attacks. Through AI models for businesses and AI agents trained to recognize attack patterns, we can anticipate malicious behaviors and block impersonation attempts before they reach the user's inbox. These systems, integrated with Power BI, generate monitoring dashboards that facilitate informed decision-making for security teams. At Q2BSTUDIO, we help organizations build a defense-in-depth architecture, combining AWS and Azure cloud services with proprietary artificial intelligence tools, all orchestrated to minimize the attack surface and maintain business continuity. Facing threats like EvilTokens, the only effective response is a comprehensive strategy that unites technology, processes, and talent. To learn more about how to protect your organization, visit our cybersecurity and pentesting section or discover how artificial intelligence for businesses can be your best ally in the fight against cybercrime.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.