---
title: "Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure"
url: https://daily.dev/posts/threat-actors-abuse-railway-com-paas-as-microsoft-365-token-attack-infrastructure-8rnjyqkud
source_url: https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign
type: article
source: "Huntress Blog"
published: 2026-05-31T07:43:22.463Z
updated: 2026-05-31T08:07:05.897Z
tags: ["microsoft"]
reading_time: 20
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructure

**[Huntress Blog](https://daily.dev/sources/huntress-blog)** · 20 min read · 0 upvotes · 0 comments

## Summary

Huntress has documented an active, large-scale device code phishing campaign abusing Railway.com PaaS infrastructure to harvest Microsoft 365 OAuth tokens across 344+ organizations in the US, Canada, Australia, New Zealand, and Germany. The campaign, attributed to the EvilTokens Phishing-as-a-Service platform, uses Railway's clean IP reputation to bypass Microsoft Identity Protection risk scoring. Attackers deploy AI-assisted, personalized phishing lures (construction RFPs, DocuSign impersonation, voicemail notifications) through multi-hop redirect chains that abuse legitimate security vendor URL rewriters (Cisco, Trend Micro, Mimecast) and platforms like Cloudflare Workers, Vercel, and AWS Amplify. Device code phishing bypasses MFA entirely by tricking victims into entering attacker-generated OAuth codes at the legitimate Microsoft endpoint, yielding persistent refresh tokens valid for up to 90 days. Huntress responded by pushing Conditional Access Policies blocking Railway IP ranges across eligible tenants. Detection queries for Microsoft Sentinel and a full list of IOCs including Railway CIDR blocks are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign>

## Similar posts on daily.dev

- [EvilTokens Campaign Reveals Device Code Phishing Ticks Up 1,380%, Powered by AI](https://daily.dev/posts/eviltokens-campaign-reveals-device-code-phishing-ticks-up-1-380-powered-by-ai-mreylstuo) · Security Boulevard · 0 upvotes · 0 comments
- [Token Bingo: Don’t Let Your Code be the Winner](https://daily.dev/posts/token-bingo-don-t-let-your-code-be-the-winner-rxegjpk08) · Arctic Wolf · 0 upvotes · 0 comments

---

Tags: [#microsoft](https://daily.dev/tags/microsoft)

[View this post on daily.dev](https://daily.dev/posts/threat-actors-abuse-railway-com-paas-as-microsoft-365-token-attack-infrastructure-8rnjyqkud)
