EvilTokens is a Phishing-as-a-Service platform that weaponizes the legitimate Microsoft 365 OAuth Device Code authorization flow. Victims authenticate against real Microsoft infrastructure — MFA fires and passes — yet the attacker captures the resulting refresh token and replays it twice daily from Railway.com PaaS infrastructure for up to 90 days. No credential database. No harvested passwords. Just a permanent session token. This investigation confirms the primary C2 domain is still live, identifies a previously undocumented co-hosted domain on the same Cloudzy backend, and maps the full 7-step kill chain.
The primary EvilTokens MailVault C2 domain techroboticslabmade.com resolves to Cloudflare anycast IPs 104.21.29.34 and 172.67.171.74. The domain returns HTTP 403 on all probed paths — root, /api/device/start, /api/device/status/, /health, /robots.txt, /login. This is Cloudflare gating the backend, not a takedown: the nameservers are ELLE.NS.CLOUDFLARE.COM and NICOLAS.NS.CLOUDFLARE.COM, indicating the operator actively manages DNS through Cloudflare.
CertSpotter reveals a wildcard certificate (*.techroboticslabmade.com) issued 2026-06-02 — four months after campaign launch, three months after the March 2 campaign acceleration. This renewal signals active operational maintenance of the platform, not abandonment. The domain was registered 2025-07-14 via Cloudflare, Inc. as registrar — 7 months of pre-campaign infrastructure preparation.
Reverse IP lookup against 216.126.227.101 (the RouterHosting/Cloudzy backend previously identified as the macmamo.com PHP host) returns two domains: macmamo.com and notificationsmanagersec.com. The second domain is not present in any published EvilTokens threat report reviewed during this investigation.
notificationsmanagersec.com was registered 2026-03-10 via NameSilo — exactly 8 days after the March 2 campaign acceleration identified by Huntress. Registration during active campaign expansion, on the same C2 backend, with a name pattern matching operator alert infrastructure ("notifications manager security") is strong co-location evidence. No MX record and no SPF record — Telegram exfiltration model, consistent with all other EvilTokens infrastructure. The domain returns HTTP 000 on all paths, indicating the Cloudzy backend is selectively offline or port-filtered.
EvilTokens does not harvest credentials. It hijacks the OAuth Device Authorization Grant (RFC 8628), a flow designed for input-limited devices like smart TVs. The attacker initiates a device code request, presents the victim with a real Microsoft URL and a legitimate-looking code, waits for the victim to authenticate normally (MFA included), and captures the resulting refresh token. The victim's login succeeds — no error, no redirect warning. The token is what the attacker needs.
Token replay occurs twice daily from Railway.com infrastructure — observed at 11:00 AM and 8:00 PM — granting persistent access to the compromised mailbox, OneDrive, calendar, and contacts for up to 90 days per token without any further victim interaction.
https://login.microsoftonline.com/{tenant}/oauth2/v2.0/devicecode with a chosen client_id. Response: user_code (short alphanumeric), device_code, verification_uri (real Microsoft URL), 15-minute expiration window.microsoft.com/devicelogin, enters the user_code, completes normal MFA. Microsoft's own infrastructure handles authentication. The victim sees a successful login — no anomaly visible./oauth2/v2.0/token with the device_code every few seconds. On victim approval, Microsoft returns an access token + long-lived refresh token scoped to mailbox, files, calendar, and contacts.BAV2ROPC. Synthetic mobile UA to evade risk scoring: iPhone OS 18.7 / Version/26.3 (Version/26.3 did not exist in early 2026 — fabricated). Signal in Entra ID logs: cmsi session (87.4% of events).The token replay infrastructure runs entirely on Railway.com PaaS, exploiting the platform's clean IP reputation to pass Microsoft's risk scoring. Five Railway IPs account for the vast majority of observed token authentication polling. Three of those five — 162.220.234.41 (254 events), 162.220.234.66 (132 events), and 162.220.232.57 (97 events) — account for approximately 84% of all observed events. This concentration indicates a centralized backend rather than distributed ephemeral deployment.
The Railway CIDR blocks are registered under RLWY-METALGEN1-01 (ARIN handle). Two CIDR blocks cover the entire EvilTokens relay footprint: 162.220.232.0/22 and 162.220.234.0/22. Blocking these at the Entra ID Conditional Access layer eliminates the persistent replay mechanism even when the refresh token itself is active. Additional secondary CIDRs observed in lower-volume events: 152.55.176.0/20, 208.77.244.0/22, 66.33.22.0/23, 69.46.46.0/24, 69.9.164.0/22, IPv6 2607:99c0::/32.
EvilTokens exhibits three unique detection signals that allow SIEM-level hunting in Entra ID sign-in logs without requiring network-level visibility:
1. BAV2ROPC user-agent: The automated token polling script uses the user-agent string BAV2ROPC. This is not a legitimate browser UA. It appears in Microsoft's Unified Audit Log under UserAgent for the token replay events. Any occurrence of BAV2ROPC in M365 sign-in logs is indicative of automated credential or token stuffing.
2. Synthetic mobile UA: To evade risk-based conditional access scoring, the kit inserts a fake iPhone UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.3 Mobile/15E148 Safari/604.1. The Version/26.3 field did not exist in early 2026 — iOS Safari uses Version/17 or Version/18. This fabricated string is a reliable SIEM signature.
3. Non-standard HTTP header: EvilTokens landing pages served through Railway.com include X-Antibot-Token as a non-standard response header. This is the platform's bot detection mechanism and functions as a fingerprint — any page serving this header in an M365 authentication context is EvilTokens infrastructure.
4. Entra ID session flag: Successful device code phishing events appear in sign-in logs with cmsi session designation — observed in 87.4% of confirmed EvilTokens compromise events.
EvilTokens compromised organizations across 7 countries: United States, Canada, France, Australia, India, Switzerland, and the UAE. France and Germany are confirmed EU victim countries. The platform launched on the NOIRLEGACY GROUP Telegram channel on February 16, 2026, offering three operator products: "B2B Sender" (outbound BEC mail via compromised accounts), "Office 365 Capture Link" (device code landing page kit), and "SMTP Sender" (bulk mail relay via captured credentials).
Post-compromise monetization uses a LLaMA-based inbox summarization module that reads the victim's email, extracts open invoices, wire transfer instructions, vendor relationships, and financial patterns — then drafts BEC emails that pass SPF/DKIM/DMARC because they originate from the compromised account itself. The sectors most impacted: construction, real estate, financial services, legal services, and healthcare — all high-value BEC targets with frequent wire transfers.
EU regulatory exposure: email access without authorization is a GDPR Art. 32 breach (inadequate security of personal data). Each compromised EU mailbox containing employee or client personal data is a reportable incident under Art. 33 (72-hour notification). Affected French organizations must notify CNIL. German organizations notify BSI and relevant Landesbehörden.
Token replay infrastructure operating from Railway CIDRs 162.220.232.0/22 and 162.220.234.0/22. Five IPs identified; three account for 84% of M365 authentication polling events. Request: investigate and terminate EvilTokens tenants.
macmamo.com and notificationsmanagersec.com both resolve to 216.126.227.101 (RouterHosting/Cloudzy, CIDR 216.126.224.0/20). macmamo.com = PHP backend; notificationsmanagersec.com = newly discovered co-hosted IOC. Request server suspension.
techroboticslabmade.com is CF-fronted (nameservers ELLE/NICOLAS.NS.CLOUDFLARE.COM). Wildcard cert active. Domain functions as EvilTokens MailVault C2. Request: DNS uncloaking + account suspension.
France confirmed as victim country. EvilTokens device code phishing campaign, 340+ orgs compromised across 7 countries from February 2026. Full IOC set and Railway.com CIDR blocks provided for defensive dissemination.
Multi-country corporate compromise operation (France, Germany, Switzerland). NOIRLEGACY GROUP Telegram channel as advertiser. Active PhaaS platform with 340+ confirmed victims. Full kill chain and IOC set enclosed.
Abuse of Microsoft OAuth Device Authorization Grant (RFC 8628). Specific client_ids may be identified in sign-in log analysis. Request: review whether known EvilTokens client_ids can be revoked at the tenant level or blocked via Entra ID risk signals.
| Type | Indicator | Context |
|---|---|---|
| Domain | techroboticslabmade.com | Primary MailVault C2 — Cloudflare-fronted — LIVE HTTP 403 |
| Domain | macmamo.com | PHP backend — Cloudzy Tampa 216.126.227.101 |
| Domain | notificationsmanagersec.com | NEW IOC — co-hosted at 216.126.227.101 — created 2026-03-10 — NameSilo |
| IP | 216.126.227.101 | RouterHosting/Cloudzy Tampa — PHP backend + NEW co-host |
| IP | 162.220.234.41 | Railway.com — 254 token replay events — primary relay |
| IP | 162.220.234.66 | Railway.com — 132 token replay events |
| IP | 162.220.232.57 | Railway.com — 97 token replay events |
| IP | 162.220.232.99 | Railway.com — 38 events (SAML-specific) |
| IP | 162.220.232.235 | Railway.com — 15 events |
| CIDR | 162.220.232.0/22 | Railway.com — block in Entra ID Conditional Access |
| CIDR | 162.220.234.0/22 | Railway.com — block in Entra ID Conditional Access |
| CIDR | 152.55.176.0/20 | Railway secondary relay CIDR |
| CIDR | 208.77.244.0/22 | Railway secondary relay CIDR |
| CIDR | 66.33.22.0/23 | Railway secondary relay CIDR |
| CIDR | 69.9.164.0/22 | Railway secondary relay CIDR |
| CIDR | 2607:99c0::/32 | Railway IPv6 relay block |
| Domain | adobe-lg7.emily-c57.workers.dev | CF Workers lure — HTTP 403 (Cloudflare suspended) |
| Domain | docusign-wz7.emily-c57.workers.dev | CF Workers lure — HTTP 403 (Cloudflare suspended) |
| Domain | docusign-2vh.davidvallejo-tophattx-com-s-account.workers.dev | CF Workers lure — HTTP 403 (Cloudflare suspended) |
| UA String | BAV2ROPC | Automated token replay UA — hunt in Entra ID SignInLogs |
| UA String | Version/26.3 (iPhone OS 18_7) | Fake iOS UA — Version/26.3 never existed in 2026 |
| HTTP Header | X-Antibot-Token | EvilTokens landing page fingerprint header |
| Log Signal | cmsi session | Entra ID sign-in flag — 87.4% of EvilTokens events |
| Telegram | NOIRLEGACY GROUP | Advertiser channel — EvilTokens first post Feb 16, 2026 |
| API Path | /api/device/start | EvilTokens device code initiation endpoint |
| API Path | /api/device/status/ | EvilTokens polling endpoint |