Proxy requests to EvilTokens PhaaS phishing domains (Cloudflare Workers, Railway.app)

Alerts on proxy requests to Cloudflare Workers or Railway.app URLs associated with EvilTokens phishing PhaaS kit infrastructure.

FreeReviewedSigma · Low · v5
Category
proxy
Author
uniqu3-us3r (SigmaHQ), DRL 1.1
Published
2026-04-28
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies outbound web proxy requests where the requested URL matches specific Cloudflare Workers and Railway.app patterns associated with EvilTokens phishing-as-a-service infrastructure. Such infrastructure is used to carry out device code authorization phishing, which can capture credentials or authorization responses after a user clicks a phishing link. The detection relies on proxy telemetry containing the full request URL.

Related detections9 linkedT1566.002 — drag to rearrange
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
Malicious Credential Harvesting Request via All-in-1 PHP Endpoint (via proxy)
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Suspicious 0ktapus Phishing Kit Credential Post Path Access
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Malicious LOLBin Spawned by Outlook via MonikerLink CVE-2024-21413
Proxy requests to EvilTokens PhaaS phishing domains (Cloudflare Workers, Railway.app)
Pivot detection · T1566.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.