Cybersecurity
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Published
4 days agoon
By
Jon Tru
Microsoft has disrupted EvilTokens, a cybercrime platform that used AI-powered tools and device-code phishing to help attackers compromise email accounts and prepare business email compromise and financial fraud campaigns.
The technology giant said the service was connected to more than 12,000 compromised mailboxes across over 10,000 organizations worldwide. The disruption was carried out with authorization from the U.S. District Court for the Eastern District of Virginia and involved multiple cybersecurity, technology and financial-sector partners.
Microsoft tracks the operators responsible for developing and supporting EvilTokens under the name Storm-2992.
Two Suspects Arrested in the UK
The disruption coincided with an operation by the Metropolitan Police Service, which arrested two men, aged 32 and 38, on September 11, 2026, in connection with the alleged commercial operation of the service.
Microsoft said EvilTokens represented a broader evolution of phishing-as-a-service by combining account takeover capabilities with automated analysis of compromised mailboxes and tools intended to facilitate fraud.
The platform reportedly included an AI-style chatbot that could examine stolen emails, identify important business relationships and locate conversations involving payments, invoices and other financially sensitive activities.
EvilTokens Abused Microsoft’s Device Authorization Process
EvilTokens was first documented in early 2026 as a phishing-as-a-service operation exploiting the OAuth 2.0 device authorization flow.
Instead of directly asking victims to provide their passwords to attackers, the scheme attempted to persuade them to authenticate a device controlled by the attacker.
A typical attack began with a deceptive email containing a malicious link or attachment. Victims were then shown a device code and directed toward Microsoft’s legitimate device-login page.
If the victim entered the code and completed authentication, the attacker could obtain access and refresh tokens associated with the account. These tokens could subsequently be abused to access email and maintain unauthorized access.
The attackers could also use compromised accounts to create malicious inbox rules, register additional devices or extract sensitive messages.
AI Tools Helped Attackers Analyze Stolen Emails
One of the most significant features of EvilTokens was its use of AI to automate tasks that traditionally required considerable experience.
The platform could reportedly summarize and translate emails, identify organizational roles, map trusted relationships and locate conversations involving financial transactions.
It also included functions designed to identify:
- Wire-transfer discussions
- Vendor invoices
- Employees involved in financial activities
- Trusted business contacts
- Potential impersonation targets
The service could then assist criminals in preparing messages designed to impersonate trusted individuals.
Security researchers said this combination effectively brought several stages of business email compromise into a single commercial platform.
Commercial Cybercrime Model
EvilTokens was reportedly marketed through Telegram and offered several paid products and services.
Among the advertised offerings were an EvilTokens B2B Sender, an Office 365 Capture Link and an SMTP Sender. The Office 365 capture product was associated with the device-code phishing functionality.
Reports indicated that customers could pay an initial fee for access to the administration panel, followed by recurring subscription charges for continued access to phishing infrastructure and related functionality.
The platform also offered supporting features such as anti-bot redirection, email delivery tools and customizable phishing campaigns.
Cryptocurrency Transactions Traced
Coinbase said its investigation identified approximately $1.1 million in EvilTokens-related revenue across four Tron addresses between October 2025 and June 2026.
The cryptocurrency exchange also identified more than 1,000 deposits originating from over 700 separate addresses, highlighting the scale of the service’s financial activity.
Researchers said the platform’s customers used numerous phishing themes, including invoices, requests for proposals and shared documents, to lure potential victims.
How the Device-Code Attacks Worked
The attack chain relied on social engineering rather than directly stealing passwords.
After a victim interacted with a malicious link or attachment, the infrastructure could generate a legitimate device authentication code and display it to the victim. The victim was then encouraged to complete the authentication process through Microsoft’s genuine login service.
If authentication was successfully completed, the attacker’s session could receive authorization tokens associated with the victim’s account.
Attackers could subsequently use the access to steal email information, create persistence mechanisms or search for communications that could support financial fraud.
EvilTokens also reportedly used multiple redirection stages and legitimate cloud infrastructure, including services from major providers, to make malicious traffic harder for security systems to distinguish from normal enterprise activity.
Thousands of Organizations Affected
Microsoft said EvilTokens had been associated with more than 12,000 compromised email inboxes belonging to over 10,000 organizations.
Victims were identified in several countries, including the United States, Canada, United Kingdom, Australia, India and France.
Industries reportedly targeted by the campaigns included:
- Financial services
- Healthcare
- Construction
- Real estate
- Wholesale distribution
- Higher education
The figures demonstrate how phishing-as-a-service platforms can extend sophisticated account-compromise techniques to a much broader group of criminals.
Microsoft Seizes 50 Websites
As part of the disruption, Microsoft and its partners seized 50 websites associated with EvilTokens and disabled more than 150 additional domains linked to its infrastructure.
The operation involved organizations including Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs.
SpyCloud said it provided intelligence from recovered phishing data involving 8,708 unique victim accounts. Those accounts were associated with 6,585 corporate email domains across 79 countries, with the earliest identified captures dating back to February 2026.
AI Lowers the Barrier for Cybercrime
The EvilTokens operation also highlights growing concerns about the use of AI to automate cybercrime.
Researchers said parts of the toolkit appeared to have been developed with AI assistance, allowing operators to package complex tasks such as mailbox analysis, target identification and fraud preparation into a commercial interface.
Rather than requiring attackers to possess expertise in identity attacks, cloud systems, social engineering and financial fraud separately, the service brought many of those capabilities together.
Microsoft’s disruption demonstrates the increasing importance of cooperation between technology companies, cybersecurity firms, financial organizations, law enforcement agencies and infrastructure providers in tackling commercial cybercrime platforms.
You may like
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

