Last Update: 08/01/2026 at 2:00 PM EST

Phishing Kits Hijack Microsoft 365 Tokens

Coverage from BleepingComputer, The Record, and others

Articles

9

Active Days

141

The Topic

Phishing Kits Hijack Microsoft 365 Tokens topic image

Cybercriminals are increasingly using device-code phishing, malicious OAuth applications, and adversary-in-the-middle techniques to obtain valid Microsoft 365 authentication tokens without directly stealing passwords or MFA codes. Platforms including Tycoon2FA, ARToken, Forg365, and Kali365 package these methods into phishing-as-a-service offerings that support campaign delivery, token management, mailbox monitoring, and access to Microsoft cloud data. The activity matters because completed legitimate authentication can give attackers persistent access to Outlook, Teams, OneDrive, SharePoint, and connected single sign-on services.

First Article: 02/19/26

Latest Article: 07/09/26

Summary

  • Device-code phishing tricks victims into approving attacker-controlled devices through Microsoft’s legitimate device-login workflow.
  • Tycoon2FA, ARToken, Forg365, and Kali365 show a growing market for packaged Microsoft 365 token-theft services.
  • Stolen access and refresh tokens can enable access to Outlook, Teams, OneDrive, SharePoint, and connected SSO applications.
  • Post-compromise features include mailbox keyword monitoring, malicious inbox rules, email sending, token refresh, and cloud-file theft.
  • Operators are adding AI-generated lures, multi-tenant campaign controls, anti-analysis checks, and infrastructure built on legitimate cloud services.
  • OAuth redirect abuse remains a related attack path, including adversary-in-the-middle phishing and malware delivery through redirected downloads.
  • Recommended defensive measures consistently include restricting device-code authentication, auditing OAuth grants, monitoring Entra sign-ins, and revoking tokens after suspected compromise.

History

07/23/2026

The story broadens from device-code phishing tied mainly to token theft into a wider Microsoft identity-abuse ecosystem that now explicitly includes OAuth redirect abuse and adversary-in-the-middle phishing. It also places more emphasis on commercialized phishing services and their post-compromise capabilities against Microsoft cloud data and connected SSO apps.

07/23/2026

The story now frames the activity less as a general wave of MFA-bypassing attacks and more as a packaged OAuth-abuse ecosystem built around phishing-as-a-service operators and affiliates. It also adds a clearer operational shift toward token-management, persistence, and post-compromise automation, including a reported disruption and recovery cycle for Tycoon2FA.

Full History

Featured

Timeline: 141 Days

Feb 19Mar 19Apr 16May 14Jun 11Jul 9

Additional Articles

⭐⭐⭐⭐⭐

The Record / Jonathan Greig05-22-2026
The FBI warned about Kali365, a Telegram-based phishing-as-a-service used to steal OAuth tokens and compromise Microsoft 365 accounts.
BleepingComputer / Bill Toulas03-03-2026
Government and public sector users targeted by phishing campaigns using oauth redirects to attacker controlled infrastructure recently to access data.
Security Affairs / Pierluigi Paganini05-05-2026
Microsoft disclosed mid-April 2026 code-of-conduct phishing that captured authentication tokens from over 35,000 users in 26 countries, with most victims in the United States.

⭐⭐⭐

BleepingComputer / Bill Toulas02-19-2026
Threat actors used device-code phishing and vishing in 2020s campaigns to abuse Microsoft OAuth device authorization and access Microsoft Entra accounts across corporate environments.
BleepingComputer / Bill Toulas03-31-2026
Sekoia reports EvilTokens device code phishing abuses OAuth 2.0 to steal Microsoft access and refresh tokens, enabling business email compromise across multiple countries.
BleepingComputer / Bill Toulas04-03-2026
Push Security and Sekoia reported increased device code phishing in 2024, where OAuth 2.0 Device Authorization Grant abuse leads to account takeover via approved tokens.