Microsoft Disrupts EvilTokens Phishing Platform Following 12,000 Account Compromises
Share
Microsoft’s Digital Crimes Unit (DCU) has disrupted the EvilTokens phishing-as-a-service (PhaaS) platform, which was responsible for compromising more than 12,000 Microsoft accounts across 10,000 organisations.
The disruption involved a coordinated effort between Microsoft, law enforcement, the Health-ISAC, and the identity threat protection company SpyCloud. Following the investigation, the Metropolitan Police Service arrested two men, aged 32 and 38, at addresses in Canary Wharf and Nine Elms in London. Both suspects, believed to be administrators of the EvilTokens website, have been released on bail pending further investigation.
AI-Powered Phishing and Device-Code Abuse
Microsoft tracks the threat actor behind the platform as Storm-2992. The group utilised the EvilTokens platform to execute sophisticated business email compromise (BEC) campaigns, targeting sectors including healthcare, financial services, construction, and higher education.
The service specialised in device-code phishing, a technique that abuses the legitimate OAuth 2.0 device-authorisation flow. This flow is designed for devices with limited input capabilities, such as smart TVs, printers, or conferencing equipment. By initiating a device-code request and sending the code to a target as part of a phishing lure, attackers can obtain authentication tokens that bypass multi-factor authentication (MFA) protections without needing to steal actual user credentials.
EvilTokens also integrated artificial intelligence to enhance its operations. The platform used AI-powered tools to customise phishing lures and sift through compromised inboxes to identify high-value targets. Once access was gained, the service used Microsoft Graph to map organisational relationships and search for sensitive information, such as wire-transfer details, pending invoices, and executive correspondence.
Impact and Residual Risks
Data from SpyCloud indicates that the platform’s impact was widespread, with more than 8,708 compromised accounts identified across 6,585 corporate email domains in 79 countries. Approximately 97.5% of the affected accounts belonged to enterprise domains, with the United States, Canada, Australia, and the United Kingdom among the most targeted nations.
While the operation successfully seized active infrastructure associated with the service, Microsoft noted that the disruption does not constitute a full takedown. The threat remains active, and affiliates have already developed clones of the platform, such as APToken.
To defend against device-code phishing, organisations should disable device-code authentication where it is not strictly required and block the device-code flow wherever possible. Security experts also recommend implementing phishing-resistant authentication methods, such as FIDO2 security keys or passkeys, and monitoring for suspicious login activity.




Leave a Reply