LOADING

Type to search

Microsoft Takes Down EvilTokens After 12,000 Inbox Compromises

Cyber Threat News

Microsoft Takes Down EvilTokens After 12,000 Inbox Compromises

Share
Microsoft Takes Down EvilTokens After 12,000 Inbox Compromises

Microsoft has disrupted EvilTokens, a phishing-as-a-service platform that was linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. The service used device-code phishing to gain access to Microsoft accounts and then used AI-powered tools to analyze compromised mailboxes and help attackers identify opportunities for further fraud.

The operation highlights how cybercriminals are combining established phishing techniques with AI to automate parts of an attack that once required considerable manual effort. Instead of simply stealing login credentials, EvilTokens gave attackers tools to understand the information inside compromised inboxes, identify financial conversations and trusted business relationships, and prepare potential business email compromise attacks.

Microsoft’s Digital Crimes Unit worked with industry partners and law enforcement to disrupt the infrastructure behind EvilTokens. Microsoft says the operation resulted in the seizure of 50 websites and the disabling of more than 150 additional domains connected to the service. Two men were also arrested in the United Kingdom in connection with the investigation.

What Is EvilTokens?

EvilTokens was a phishing-as-a-service platform that allowed cybercriminals to use an existing attack infrastructure instead of building their own tools. Microsoft says the service appeared in February 2026 and was promoted through Telegram.

According to Microsoft’s investigation, customers reportedly paid $1,500 to access the service, followed by a $500 monthly fee. The platform provided phishing templates, infrastructure for authentication-token theft, mailbox analysis capabilities, and AI-assisted tools that could help attackers identify potential targets and fraud opportunities.

Microsoft associates the operation with a threat actor it tracks as Storm-2992. The service was designed to make device-code phishing more accessible to criminals who wanted to compromise Microsoft accounts and use the stolen access for follow-up attacks.

How Did the EvilTokens Attack Work?

One of the most important elements of EvilTokens was its use of device-code phishing. Device-code authentication itself is a legitimate Microsoft authentication method. It is intended for situations where users need to authenticate on devices that may not have a conventional web browser or keyboard.

Attackers abused this legitimate process by persuading victims to complete an authentication request that had actually been initiated by the attacker.

A victim could receive a message containing a device code and instructions to complete a Microsoft sign-in. The victim would then visit Microsoft’s legitimate authentication page and enter the code. Because the authentication page itself could be genuine, the process might not look like a conventional phishing attack.

The problem was that the code was connected to the attacker’s authentication session. When the victim completed the process, the attacker could receive authentication tokens that allowed access to the victim’s account.

This means the attacker didn’t necessarily need to steal the victim’s password. The victim could effectively authenticate the attacker’s session without realizing what was happening.

Why MFA Didn’t Necessarily Stop the Attack

Multifactor authentication is an important security control, but device-code phishing shows why MFA doesn’t eliminate every form of account compromise.

In a device-code attack, the victim may actually complete the expected authentication process, including any required verification. The problem is that the victim has been tricked into approving an authentication request that was initiated by someone else.

Microsoft says EvilTokens used stolen authentication tokens to access compromised accounts and could also use techniques such as device registration and malicious inbox rules to maintain access.

This is one reason organizations need to look beyond passwords and MFA when investigating suspicious account activity. Authentication logs, device registrations, mailbox rules, sessions, and tokens can all provide important clues after a suspected compromise.

What Happened After the Attackers Got Into the Inbox?

Getting access to an employee’s inbox was only the beginning of the EvilTokens attack.

A compromised business mailbox can contain a huge amount of useful information. It may reveal who handles payments, which vendors the company works with, which invoices are awaiting approval, who communicates with senior executives, and which employees have authority over financial transactions.

Attackers traditionally had to search through these messages manually. EvilTokens attempted to automate much of that work.

Microsoft says the platform’s AI capabilities could analyze mailbox content, summarize messages, translate emails, identify financial discussions, and map relationships between people inside an organization. The tools could also help attackers identify trusted contacts and information that could be useful in a fraud campaign.

This changes the value of a compromised inbox. An attacker doesn’t just gain access to someone’s email. They can potentially gain a detailed view of how the organization communicates and conducts business.

AI Helped Attackers Identify Potential Targets

Business email compromise attacks depend heavily on context. An attacker who knows how a company’s finance department works can create a much more convincing fraudulent request than someone who sends a generic phishing email.

EvilTokens attempted to automate this intelligence-gathering process.

Microsoft says the AI assistant could help attackers identify potential fraud strategies and prepare messages that impersonated trusted contacts. This could include using information from existing email conversations to make fraudulent communications appear more legitimate.

The important point is that AI wasn’t simply being used to write phishing emails. It was being used to help attackers understand the victim’s environment.

That makes an already serious account compromise more dangerous because the attacker can potentially move from initial access to targeted fraud much faster.

EvilTokens Used Multiple Phishing Themes

Microsoft’s technical analysis found that EvilTokens supported 44 different phishing themes. These themes were designed to imitate the kinds of communications employees regularly receive at work.

The lures included invoices, requests for proposals, shared documents, document-signing requests, voicemail notifications, password expiration warnings, and other business-related messages. The phishing campaigns could use malicious links as well as PDF and HTML attachments.

The infrastructure also used multiple stages to make the attacks harder to detect. Microsoft found evidence of redirects, compromised websites, legitimate cloud services, and fake CAPTCHA pages being used as part of the attack chain.

For employees, this makes awareness particularly important. A phishing email doesn’t always contain obvious spelling mistakes or an unrealistic offer. It can look like an ordinary work-related request.

Organizations Across Multiple Industries Were Targeted

EvilTokens was not focused on a single industry. Microsoft observed compromised organizations in financial services, healthcare, construction, real estate, higher education, wholesale distribution, and other sectors.

The activity was observed across several countries, including the United States, Canada, the United Kingdom, Australia, India, and France. Microsoft says more than 12,000 email inboxes belonging to more than 10,000 organizations were compromised.

The numbers show how quickly a phishing-as-a-service operation can scale. A single criminal group doesn’t need to personally target every victim. Once the infrastructure is packaged as a service, multiple customers can use it to conduct their own campaigns.

Microsoft Seized 50 EvilTokens Websites

Microsoft’s Digital Crimes Unit worked with partners to disrupt the infrastructure supporting EvilTokens.

The company says it obtained legal authority to seize 50 websites associated with the operation and disable more than 150 additional domains. The legal action was filed in the U.S. District Court for the Eastern District of Virginia.

Microsoft also reported that two men were arrested in the United Kingdom as part of the investigation. The arrests and legal proceedings are separate from Microsoft’s technical disruption of the infrastructure.

The takedown removes a significant portion of the infrastructure used by EvilTokens, but it doesn’t eliminate device-code phishing as a technique.

AI Was Also Used to Build the Criminal Platform

There is another unusual aspect of the EvilTokens investigation. Microsoft says its researchers found evidence that AI had been used to help develop parts of the criminal platform.

Microsoft described some of the development as “vibe coding,” where AI tools were used to generate or assist with software development. The platform itself then used AI to help criminals analyze compromised inboxes and identify useful information.

This creates a different kind of cybersecurity concern. AI can reduce the amount of technical knowledge and manual effort required to build certain tools. It can also help automate repetitive tasks after an account has been compromised.

In the case of EvilTokens, those capabilities were combined into a service that criminals could access for a monthly fee.

Why Device-Code Phishing Deserves Attention

Device-code phishing isn’t a new technique. The concern is the way services such as EvilTokens can package the technique and make it easier for multiple threat actors to use.

Microsoft says EvilTokens was part of a broader trend involving the abuse of device-code authentication for phishing and account compromise.

For employees, one of the simplest precautions is to question unexpected authentication requests. If an email or message suddenly asks you to enter a device code, particularly when you weren’t trying to sign in to a new device, stop and verify the request.

The fact that the sign-in page belongs to Microsoft doesn’t automatically mean the authentication request itself is safe. The attacker may be using a legitimate authentication process for an illegitimate purpose.

How Businesses Can Protect Against EvilTokens-Style Attacks

Organizations can reduce the risk by reviewing whether device-code authentication is actually required in their environment. Microsoft recommends blocking device-code authentication where it isn’t needed and using narrowly defined exceptions when legitimate business requirements exist.

Organizations should also consider phishing-resistant authentication methods such as passkeys and FIDO2 security keys. These technologies are designed to provide stronger protection against phishing-based authentication attacks.

Security teams should monitor authentication activity for unusual device-code requests, unexpected device registrations, suspicious Microsoft Graph activity, and changes to mailbox rules. These indicators can help identify account compromise after an attacker has obtained an authentication token.

Mailbox rules deserve particular attention. An attacker who gains access to an employee’s account may create rules that hide messages or redirect emails. This can make it easier to continue a fraud campaign without the victim noticing suspicious activity.

Organizations should also remember that changing a password may not be enough after a token-based compromise. Security teams need to investigate active sessions and revoke compromised authentication tokens as part of the incident response process.

Employee awareness remains important too. Workers don’t need to understand OAuth or authentication tokens to recognize a suspicious request. They need to know that an unexpected request to enter a device code is a reason to stop and verify the request through another channel.

EvilTokens Is Disrupted, But Device-Code Phishing Isn’t Gone

Microsoft’s operation has disrupted the infrastructure associated with EvilTokens, but the underlying attack technique remains available to other threat actors.

The larger lesson from the case is that account compromise doesn’t end when an attacker gets through the login process. A compromised mailbox can provide access to sensitive business conversations, financial information, internal contacts, invoices, and other data that can be used to build convincing follow-up attacks.

EvilTokens also shows how AI can change the speed of these attacks. Instead of manually searching through thousands of emails, criminals can use AI-assisted tools to identify relevant conversations and relationships much faster.

For businesses, protecting the login is only one part of account security. Organizations also need to monitor what happens after authentication and have a clear response process for suspicious activity.

The EvilTokens case brings several existing threats together in one attack chain: phishing, token theft, account compromise, AI-assisted analysis, and business email fraud.

And that is what makes this case worth watching. The phishing email may be the first step, but the real damage can happen after the attacker gets inside the inbox.

Author

  • New Project 18

    Maya Pillai is a technology writer with over 20 years of experience. She specializes in cybersecurity, focusing on ransomware, endpoint protection, and online threats, making complex issues easy to understand for businesses and individuals.

    View all posts
Tags:
Maya Pillai

Maya Pillai is a technology writer with over 20 years of experience. She specializes in cybersecurity, focusing on ransomware, endpoint protection, and online threats, making complex issues easy to understand for businesses and individuals.

  • 1

You Might also Like