EvilTokens Phishing Service Disrupted After Compromising 12,000 Microsoft Accounts
Microsoft’s Digital Crimes Unit (DCU) has disrupted the EvilTokens phishing-as-a-service (PhaaS) platform after it compromised more than 12,000 Microsoft accounts belonging to organizations around the world.
The operation, which debuted in February, was one of the first phishing services to support device code authentication at scale. EvilTokens also provided cybercriminals with AI-powered tools to customize phishing lures and search compromised inboxes for high-value targets.
Two suspected EvilTokens administrators arrested in the UK
Microsoft said it orchestrated an outage of EvilTokens’ infrastructure with help from Health-ISAC, law enforcement agencies, and SpyCloud, an Austin, Texas-based privacy threat protection company.
As part of the investigation, two men aged 32 and 38 who are suspected of administering the EvilTokens website were arrested in the United Kingdom.
The Metropolitan Police received information about the suspects in August and executed warrants at addresses in Canary Wharf and Nine Elms on Friday. Both men were released on bail pending further investigation.
“The Metropolitan Museum of Art remains committed to holding accountable those who facilitate criminal enabling capabilities and think they can remain undetected. We will find you and take action,” Lt. Celina D’Adamo told BleepingComputer.
EvilTokens targeted businesses across multiple industries
Microsoft tracks the EvilTokens threat actor as Storm-2992. The campaign affected organizations in the wholesale distribution, construction, financial services, real estate, higher education, and healthcare sectors.
Microsoft said EvilTokens compromised more than 12,000 inboxes belonging to over 10,000 organizations worldwide, supporting what it described as an “advanced business email compromise (BEC) campaign.”
Data retrieved by SpyCloud identified more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries. Approximately 97.5% of the compromised accounts belonged to enterprise domains.
The United States was the most targeted country, followed by Canada, Australia, the United Kingdom, and Saudi Arabia.

Source: SpyCloud
How EvilTokens used device code phishing to bypass MFA
Device code phishing exploits legitimate Microsoft OAuth 2.0 device authentication flows. These flows are designed for devices with limited input capabilities, including smart TVs, printers, conferencing equipment, and some Teams devices.
Rather than stealing a victim’s password, attackers can use the technique to obtain authentication tokens and compromise accounts despite multifactor authentication (MFA) protections.
A device code phishing attack begins when an attacker generates a device code request and sends the resulting code to a target as part of a phishing lure. The victim is directed to a page displaying the code and a button linking to Microsoft’s legitimate login portal, where they are prompted to authenticate.
.jpg)
Source: Microsoft
Device code phishing surged this year as multiple threat actors adopted the technique. By April, at least 10 phishing platforms supported device code authentication.
EvilTokens offered phishing kits and AI-powered BEC tools
Storm-2992 promoted EvilTokens through Telegram, offering access for $500 per month or a one-time fee of $1,500.

Source: Microsoft
Additional features were sold separately, including anti-bot redirectors, B2B and SMTP sending tools, and Office 365 CaptureLink tools. The service offered 44 customizable phishing kits.
The phishing lures impersonated document-signing platforms, Microsoft services, cloud identity and file-sharing providers, billing systems, voicemail services, and eFax providers.
Common subject lines referenced construction bids, partnership agreements, compensation and benefits notices, requests for proposals, shared files, invoices, and password expiration warnings.

Source: Microsoft
After gaining access to an account, EvilTokens used Microsoft Graph to map organizational relationships. Its AI-powered tools analyzed mailbox contents and identified high-value targets within compromised environments.
The platform could search for wire transfer information, pending invoices, and executive communications. It could also generate relevant business email compromise messages based on the situation.
To evade detection, EvilTokens used multi-step redirects, PDFs, HTML attachments, and fake CAPTCHA pages. The service also routed traffic through compromised websites and legitimate cloud platforms, including Vercel, Cloudflare Workers, and AWS Lambda.
Microsoft says the threat remains active
Microsoft and its partners obtained legal authority to seize active infrastructure associated with the phishing service. However, Microsoft said the action was not a complete takedown. EvilTokens remains active, although the volume of attacks is expected to fall significantly.
EvilTokens is also not the only platform supporting device code phishing. Affiliates have already created clones, including APToken.
How organizations can defend against device code phishing
Organizations should disable device code authentication when it is not required and block the device code flow whenever possible.
Users should verify which application they are authenticating to and stop the process if they are not signing in to the expected application.
Additional mitigation steps include monitoring for suspicious login activity and using phishing-resistant authentication methods such as FIDO2 security keys and passkeys.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



