Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft has disrupted a major phishing-as-a-service (PhaaS) platform called EvilTokens, which was being used by cybercriminals to target Microsoft 365 accounts and compromise sensitive business email communications. The operation, carried out in coordination with law enforcement and other private sector organizations, involved the seizure of over 50 websites and the disabling of more than 150 supporting domains.

EvilTokens was a sophisticated platform that leveraged AI-powered tools to help attackers craft tailored phishing lures, identify high-value targets, and streamline post-compromise activity. Its capabilities were designed to facilitate business email compromise (BEC) campaigns on a massive scale, with over 12,000 inboxes compromised in more than 10,000 organizations worldwide.

The platform’s operators used a technique called device code phishing, which involved abusing Microsoft’s legitimate authentication process. When a victim clicked on a phishing link, they would be led to a malicious webpage that generated or displayed the device code before redirecting them to the legitimate Microsoft login portal. The victim would complete their normal authentication without realizing it was being hijacked by the attackers.

What makes EvilTokens particularly noteworthy is its use of AI to automate and scale phishing campaigns at an unprecedented level. According to Microsoft, the platform’s operators used artificial intelligence to analyze compromised inboxes, identify valuable conversations and relationships, map organizational structures, and ultimately build targeted follow-on strategies for BEC attacks. Attackers could also use Microsoft Graph to accelerate reconnaissance, mapping internal structures and identifying sensitive permissions.

The takedown of EvilTokens is a significant victory in the ongoing battle against cybercrime. The operation involved collaboration between multiple partners, including law enforcement agencies, private sector organizations, and cybersecurity firms. SpyCloud identified over 8,700 compromised accounts across 6,600 corporate email domains spanning 79 countries, while TRM Labs investigated the financial infrastructure behind EvilTokens operators.

As a result of this operation, Microsoft has taken action against the threat actors behind EvilTokens, who are known as “Storm-2992”. The UK’s Metropolitan Police Service cybercrime team arrested two men suspected of crimes connected to this campaign, although they have since been released on bail while the investigation continues.

The disruption of EvilTokens serves as a reminder that PhaaS platforms pose a significant threat to organizations and individuals alike. These platforms enable attackers to conduct sophisticated phishing campaigns at scale, often using AI-powered tools to evade detection. To stay safe online, it’s essential for users to remain vigilant when receiving unsolicited emails or links, and to report suspicious activity to the relevant authorities.

In light of this operation, Microsoft is urging organizations to take immediate action to protect their sensitive business email communications. This includes implementing robust security measures, such as multi-factor authentication, and regularly monitoring for signs of phishing activity. By staying informed and proactive in the face of evolving cyber threats, we can reduce the risk of falling victim to these types of attacks.


Source: Dark Reading — 2026-09-22