Authentication from EvilToken IPs (Railway.com)

Detects successful user authentications originating from IP addresses associated with known EvilToken infrastructure hosted on Railway.com. This indicates potential compromise of user accounts via phishing or other credential access techniques, where the adversary is using their infrastructure to authenticate.