Full Report
Railway PaaS is being weaponized as a clean token replay engine in an active AiTM and device code phishing campaign impacting 268+ M365 organizations and 100+ MSPs.
Analysis Summary
# Incident Report: Weaponization of Railway PaaS in EvilTokens Phishing Campaign
## Executive Summary
An active, large-scale Adversary-in-the-Middle (AiTM) and device code phishing campaign is weaponizing the Railway Platform-as-a-Service (PaaS) to replay stolen Microsoft 365 tokens. Attributed to the "EvilTokens" Phishing-as-a-Service (PhaaS) platform, the attack has impacted over 340 organizations and 100+ MSPs globally. The campaign utilizes AI-driven workflows to generate unique phishing lures that bypass traditional email filters and MFA.
## Incident Details
- **Discovery Date:** February 19, 2026
- **Incident Date:** February 19, 2026 – Ongoing
- **Affected Organizations:** 340+ M365 tenants (including Law Firms, Construction, and MSPs)
- **Sector:** Cross-sector / Multi-tenant
- **Geography:** US, Canada, Australia, New Zealand, Germany
## Timeline of Events
### Initial Access
- **Date/Time:** February 19, 2024 (First detected activity)
- **Vector:** Phishing (AiTM and Device Code Phishing)
- **Details:** Attackers send personalized, AI-generated phishing emails containing "Office 365 Capture Links" or Open Redirects to harvest credentials and session tokens.
### Lateral Movement
- **Details:** After obtaining valid session tokens, attackers use the Railway PaaS infrastructure as a "clean" proxy to authenticate as the victim, moving into the M365 environment to access sensitive communications.
### Data Exfiltration/Impact
- **Details:** Attackers target sensitive emails for wire fraud, business email compromise (BEC), and data exfiltration. The use of token replay allows them to maintain access without needing the victim’s password or a second MFA prompt.
### Detection & Response
- **Detection:** Identified by Huntress via anomalous authentication patterns originating from Railway infrastructure (e.g., `*.up.railway[.]app`).
- **Response:** Automated blocking of all authentication attempts from Railway IP space to protected identities; over 450 total compromises blocked to date.
## Attack Methodology
- **Initial Access:** Device code phishing and AiTM capture links.
- **Persistence:** Token theft and replay; session hijacking that bypasses MFA.
- **Defense Evasion:** Use of AI to vary email lures (avoiding signature-based detection) and Railway PaaS to mask the attacker's true origin.
- **Credential Access:** Theft of session tokens and primary credentials via EvilTokens PhaaS dashboards.
- **Discovery:** Automated AI workflows to identify sensitive financial data within compromised mailboxes.
- **Impact:** Financial fraud (Wire transfer redirection) and unauthorized access to corporate data.
## Impact Assessment
- **Financial:** High potential for loss via wire fraud (a primary goal of the EvilTokens kit).
- **Data Breach:** Compromise of M365 mailboxes, OneDrive files, and SharePoint data across 340+ organizations.
- **Operational:** Significant disruption for MSPs managing multiple affected tenants.
- **Reputational:** High for impacted service providers and law firms handling sensitive client data.
## Indicators of Compromise
- **Network Indicators:**
- Authentication attempts from Railway[.]app infrastructure.
- Traffic to/from `*.up.railway[.]app`.
- Phishing links utilizing Cloudflare Workers.
- **Behavioral Indicators:**
- Unusual sign-in properties (e.g., successful login from a PaaS provider IP).
- Rapid generation of unique, personalized phishing lures across a single domain.
- Use of "Device Code" flow sign-in prompts where not standard for the user.
## Response Actions
- **Containment:** Revocation of all active M365 sessions for compromised users.
- **Eradication:** Blocking of known EvilTokens redirector domains and Railway PaaS IP ranges.
- **Recovery:** Mandatory password resets and re-registration of MFA methods for affected accounts.
## Lessons Learned
- **AI-Driven Phishing:** Attackers are successfully using AI to eliminate "static" indicators in phishing emails, making traditional email security gateways less effective.
- **PaaS Abuse:** Trusted cloud platforms (Railway, Tencent, etc.) are increasingly used as attack infrastructure because their IP addresses often have a neutral or positive reputation.
- **MFA Vulnerability:** Standard MFA is insufficient against AiTM and Device Code phishing; FIDO2/Hardware keys are required for robust protection.
## Recommendations
- **Conditional Access:** Implement policies to block sign-ins from known PaaS/Hosting provider IP ranges.
- **Hardened MFA:** Transition from SMS/Push notifications to FIDO2-compliant security keys to prevent token theft.
- **Monitoring:** Set up alerts for "Device Code" authentication flows, especially when originating from unusual environments.
- **User Education:** Train users to recognize the specific "Device Code" login prompt and the dangers of entering codes into unfamiliar screens.