Huntress has documented an active, large-scale device code phishing campaign abusing Railway.com PaaS infrastructure to harvest Microsoft 365 OAuth tokens across 344+ organizations in the US, Canada, Australia, New Zealand, and Germany. The campaign, attributed to the EvilTokens Phishing-as-a-Service platform, uses Railway's clean IP reputation to bypass Microsoft Identity Protection risk scoring. Attackers deploy AI-assisted, personalized phishing lures (construction RFPs, DocuSign impersonation, voicemail notifications) through multi-hop redirect chains that abuse legitimate security vendor URL rewriters (Cisco, Trend Micro, Mimecast) and platforms like Cloudflare Workers, Vercel, and AWS Amplify. Device code phishing bypasses MFA entirely by tricking victims into entering attacker-generated OAuth codes at the legitimate Microsoft endpoint, yielding persistent refresh tokens valid for up to 90 days. Huntress responded by pushing Conditional Access Policies blocking Railway IP ranges across eligible tenants. Detection queries for Microsoft Sentinel and a full list of IOCs including Railway CIDR blocks are provided.