EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Microsoft’s Digital Crimes Unit has led a coordinated effort with law enforcement and cybersecurity companies to disrupt the EvilTokens phishing-as-a-service (PhaaS) operation, which compromised over 12,000 Microsoft accounts across more than 10,000 organizations worldwide. The takedown is a significant blow to the threat actor, known as Storm-2992, who used AI-powered features to customize lures and target high-value accounts with sophisticated business email compromise (BEC) campaigns.

EvilTokens emerged in February as one of the first PhaaS platforms to support device code authentication at scale. The platform abused Microsoft’s legitimate OAuth 2.0 device-authorization flow to obtain authentication tokens, even when multifactor authentication (MFA) protections were enabled. This technique, known as device-code phishing, has become increasingly popular among threat actors this year, with at least 10 phishing platforms supporting it by April.

The EvilTokens platform was used to fuel massive BEC campaigns, which targeted organizations in a range of sectors, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. The platform’s owners promoted and supported the service through Telegram, offering access for $500 per month or a one-time fee of $1,500. Add-ons, such as anti-bot redirectors and Office 365 capture-link tools, were sold separately.

The disruption of EvilTokens is a significant victory for Microsoft and its partners, but it’s essential to note that the threat actor still remains at large. Two individuals suspected of being administrators of the EvilTokens website were arrested in the UK last week, but they have been released on bail pending further investigation. The Metropolitan Police Service has vowed to continue pursuing those who facilitate cybercrime, promising to “find you and take action.”

The compromised accounts belonged to enterprise domains, with roughly 97.5% of affected organizations using Microsoft services. SpyCloud’s recaptured phished data shows that the platform was focused on businesses, with over 8,700 compromised accounts across 6,585 corporate email domains in 79 countries.

The takedown highlights the importance of staying vigilant against phishing attacks, particularly those that use device-code authentication to bypass MFA protections. Organizations must remain proactive in protecting their employees and customers from BEC campaigns, which can have devastating financial consequences.

So what can you do to protect yourself and your organization? First and foremost, ensure that multifactor authentication (MFA) is enabled on all accounts, especially those with access to sensitive information. Be cautious of emails that ask for device codes or prompt you to authenticate through a link. Verify the authenticity of any email by contacting the sender directly, rather than clicking on suspicious links.

Lastly, stay informed about emerging threats and phishing tactics, such as device-code phishing. Educate your employees on how to identify and report suspicious emails, and invest in robust cybersecurity measures that can detect and prevent BEC campaigns. By staying proactive and vigilant, you can reduce the risk of falling victim to these sophisticated attacks.


Source: Bleeping Computer — 2026-09-22