Cybersecurity Experts Takedown EvilTokens PhaaS Platform After Compromising 12,000 Microsoft Accounts
A major disruption has been dealt to the EvilTokens platform, a phishing-as-a-service (PhaaS) operation that compromised over 12,000 Microsoft accounts across more than 10,000 organizations worldwide. The takedown effort was led by Microsoft’s Digital Crimes Unit (DCU), in collaboration with law enforcement and identity threat protection company SpyCloud.
EvilTokens emerged in February as the first PhaaS platform to support device code authentication at scale and offer cybercriminals AI-powered features for customizing lures and sifting through compromised inboxes. The platform’s administrators used Microsoft’s legitimate OAuth 2.0 device-authorization flow, which is designed for devices with limited input capabilities, such as smart TVs and printers, to initiate phishing attacks. Attackers would send a device code to the target, who would then be directed to Microsoft’s login portal to authenticate.
The EvilTokens platform was used by multiple threat actors, who adopted its device-code phishing technique to compromise accounts without needing credential theft. This led to a surge in device code phishing this year, with at least 10 phishing platforms supporting the capability by April. According to Microsoft’s report, EvilTokens compromised over 12,000 inboxes across more than 10,000 organizations worldwide, fueling sophisticated business email compromise (BEC) campaigns.
The platform’s administrators used Telegram to promote and support EvilTokens, offering access to the service for $500/month or a one-time fee of $1,500. Add-ons such as anti-bot redirectors, B2B and SMTP sending tools, and an Office 365 capture-link tool were sold separately. The service provided 44 customizable phishing kits, which impersonated document-signing platforms, Microsoft services, cloud identity and file-sharing providers, invoicing systems, voicemail, and eFax services.
To evade detection, EvilTokens used multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages to impede automated analysis. The platform also routed traffic through compromised sites and legitimate cloud platforms such as Vercel, Cloudflare Workers, and AWS Lambda.
Two men, aged 32 and 38, suspected of being administrators of the EvilTokens website were arrested in the U.K. by the Metropolitan Police Service. They were released on bail pending further investigation.
The takedown of EvilTokens highlights the importance of robust security measures to prevent phishing attacks. Organizations must prioritize employee education and awareness about phishing tactics, as well as implement multi-factor authentication (MFA) and monitor their email accounts for suspicious activity. Individuals can also take steps to protect themselves by being cautious when receiving emails with device codes or links to login portals. By staying vigilant and up-to-date on the latest cybersecurity threats, we can reduce the effectiveness of phishing attacks like EvilTokens.
Source: Bleeping Computer — 2026-09-22