Microsoft Disrupts EvilTokens Phishing-as-a-Service Platform
The operation, which targeted Microsoft accounts using advanced device-code phishing techniques, resulted in the arrest of two suspected administrators in the U.K.

Coordinated Takedown of EvilTokens Infrastructure
Microsoft’s Digital Crimes Unit (DCU) has successfully disrupted the EvilTokens phishing-as-a-service (PhaaS) platform. This criminal operation gained notoriety for compromising more than 12,000 Microsoft accounts across 10,000 different organizations. The takedown effort was the result of a collaborative investigation involving the Health-ISAC, international law enforcement agencies, and the identity threat protection firm SpyCloud, according to reports from BleepingComputer.
Following an investigation into the platform's activities, two men aged 32 and 38 were arrested in the United Kingdom. Metropolitan Police Service officers executed warrants in Canary Wharf and Nine Elms after receiving intelligence in August. While the suspects have been released on bail as the investigation continues, authorities emphasized their commitment to pursuing those who facilitate cybercriminal operations.

The Mechanics of Device-Code Phishing
EvilTokens earned a reputation for being a sophisticated actor that specializes in device-code phishing, a methodology that significantly complicates traditional security defenses. By abusing the legitimate OAuth 2.0 device-authorization flow—which is standard for devices with limited input capabilities like printers or smart TVs—attackers were able to obtain authentication tokens even when victims had multi-factor authentication (MFA) enabled.
This technique has seen a dramatic increase in adoption across the cybercriminal landscape, as observed in recent research. The rapid proliferation of such kits has contributed to a notable surge in device code phishing attacks, creating a challenging environment for IT security teams tasked with protecting enterprise credentials.

AI-Enhanced Business Email Compromise
Beyond merely gaining access, EvilTokens provided its subscribers with AI-powered tools designed to maximize the impact of a breach. Once an account was compromised, the service utilized Microsoft Graph to map internal organizational structures. Attackers then used AI to analyze mailbox contents, identifying high-value targets such as invoices, wire transfer instructions, and executive communications to craft highly convincing business email compromise (BEC) lures.
The platform was marketed through Telegram, with access offered for $500 per month or a one-time fee of $1,500. It featured a robust suite of add-ons, including anti-bot redirectors and sophisticated capture-link tools, allowing operators to bypass automated security scanners by routing traffic through legitimate cloud platforms like AWS Lambda and Cloudflare Workers.

Scope and Industry Impact
Microsoft tracks the threat actor responsible for the platform as Storm-2992. Data provided by SpyCloud confirms that the campaign was heavily weighted toward the enterprise sector, with roughly 97.5% of compromised accounts belonging to corporate domains. Key affected sectors included financial services, construction, healthcare, higher education, and wholesale distribution.
The geographical reach of the campaign was extensive, affecting organizations in 79 countries. The United States, Canada, Australia, the United Kingdom, and Saudi Arabia were identified as the most targeted regions. Despite the disruption of the platform's infrastructure, security experts warn that the threat remains active, as affiliates have already begun shifting to alternative platforms like APToken to continue their phishing campaigns.

Defensive Measures and Future Outlook
To mitigate the ongoing risks posed by these types of phishing kits, Microsoft recommends that organizations disable device-code authentication in environments where it is not strictly required. Furthermore, administrators should monitor for suspicious login patterns and prioritize the transition to phishing-resistant authentication methods, such as FIDO2 security keys or passkeys.
Users are advised to exercise extreme caution when authenticating, explicitly verifying the application requesting the device code before proceeding. As threat actors continue to evolve their toolkits and tactics, security leaders must stay informed on how to effectively secure their infrastructure against modern threats. Interested parties can learn more about securing their environments at the upcoming digital summit, where they can save your seat for expert-led sessions on AI-powered threats.
Sources
- BleepingComputerEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts