Back Darkreading Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Microsoft and a group of private and public sector organizations recently disrupted EvilTokens, a phishing-as-a-service (PhaaS) provider that rose to prominence earlier this year.
EvilTokens is a cybercrime platform that sets threat actors up with a suite of AI-powered tools to conduct phishing campaigns. Its capabilities include phishing lure crafting and analysis of compromised inboxes to identify possible targets. As Microsoft explained in a blog post published today, "This AI-powered cybercrime platform facilitated sophisticated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide."
Microsoft identifies the operators behind EvilTokens as "Storm-2992."
This month, Microsoft, along with several partners, seized EvilTokens infrastructure as part of US court-enabled legal action. Microsoft said in a separate blog that it "seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure." Furthermore, the UK's Metropolitan Police Service cybercrime team arrested two men earlier this month suspected of crimes connected to this campaign. Both men have been released on bail as the investigation continues.
Related: AI Model Evaluator METR Hit by Credential Theft, Probing
Notably, the service was built around Microsoft 365 account takeover . The PhaaS platform's key technical capability was device code phishing or, in other words, abusing the device code authentication process.
EvilTokens' Differentiator: Automated Device Code Phishing at Scale
When a victim clicked on a link in a phishing lure, EvilTokens initiated Microsoft's legitimate device authentication process on its own; the victim would be led to a malicious Web page that generates or displays the device code before redirecting them to the legitimate Microsoft device-login portal. The victim would complete their normal authentication but inadvertently authorize the attacker's session in the process.
A Microsoft spokesperson tells Dark Reading that EvilTokens helped make device code phishing easier to deploy at scale by packaging it into a ready-made service.
"While adversary-in-the-middle phishing techniques have become more common across the cybercrime ecosystem, EvilTokens stood out for its use of AI to help operators create tailored lures, identify high-value targets, and streamline post-compromise activity," the spokesperson says. "We continue to track the threat landscape closely as these tactics evolve and will take action where appropriate."
Related: Cyera's Oasis Security Buy Is All AI Agent Control
Once the attacker got access, EvilTokens' AI capabilities would analyze compromised inboxes to identify valuable conversations and relationships, map roles within the organization, identify those with payment authority, and ultimately build a follow-on strategy for further targeted BEC attacks . Attackers could also use Microsoft Graph to accelerate reconnaissance, with Microsoft observing them "programmatically [mapping] internal organizational structures and [identifying] sensitive permissions the moment a token was secured."
EvilTokens emerged in February and expanded rapidly over the spring and summer. It was sold through Telegram for $1,500 upfront, plus $500 per month in cryptocurrency. During the course of the investigation, Microsoft teamed up with multiple partners to build out different parts of the evidentiary picture to use for legal action and victim remediation.
SpyCloud, for example, identified 8,708 compromised accounts across 6,585 corporate email domains spanning 79 countries. TRM Labs investigated the financial infrastructure and cryptocurrency flows behind EvilTokens operators. Coinbase traced payments, identified purchasers on its platform, and combined transaction, merchant, device, and open source information to help attribute the operators, ultimately referring information to law enforcement. Other partners, including Cloudflare, also contributed to the disruption.
Related: USA Fencing Lunges Into the Hidden Identity Challenge in Amateur Sports
One notable detail from SpyCloud's blog post regarding the investigation was that the top 10 most active EvilTokens customers accounted for 60% of the total unique victims in its recaptured data.
Trevor Hilligoss, chief intelligence officer at SpyCloud, tells Dark Reading he "almost certainly" sees these high-volume operators migrating to competing PhaaS services following the disruption effort, adding that some were likely running multiple phishing kits already.
"Large phishing operations keep redundancy, and they mix kits to cover techniques one platform doesn't support. A seizure preserves the record; panels hold customer accounts, chat logs, and payment traces, and every operational security mistake those users made is now evidence. Law enforcement works on its own timeline, and charges may come long after the headlines," he says. "The part we'll be watching is whether the same high-volume clusters resurface elsewhere hitting the same corporate domains."
For defenders, one of Microsoft's primary recommendations is to only allow device code flow where necessary, and to block device code flow where possible .
Senior News Writer, Dark Reading
Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere.
At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
Want more Dark Reading stories in your Google results?
The State of Cloud Security: The Latest Challenges
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Essential News & Insights from Black Hat USA 2025
Effective Alert Triage: Reducing Noise and Finding Real Threats
Effective Alert Triage: Reducing Noise and Finding Real Threats
Cybersecurity Outlook 2027
Cybersecurity Outlook 2027
Threat Exposure Analytics: Measuring and Communicating Security Risk
Threat Exposure Analytics: Measuring and Communicating Security Risk
Benchmark Scores Are a False Flag
Benchmark Scores Are a False Flag
Building an Effective Red Team: Beyond Penetration Testing
Building an Effective Red Team: Beyond Penetration Testing
Identity Attacks Overtake Exploits as Top Ransomware Cause
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
Orgs Move to SSO, Passkeys to Solve Bad Password Habits
1Password Addresses Critical AI Browser Agent Security Gap
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
