Cybersecurity

Microsoft Disrupts EvilTokens Infrastructure After More Than 12,000 Mailboxes Compromised Through Device Code Phishing

Microsoft revealed that the phishing-as-a-service platform EvilTokens enabled AI-supported attacks and affected more than 12,000 mailboxes across more than 10,000 organizations. The platform was used to exploit the device code authentication flow and steal access tokens, before Microsoft’s Digital Crimes Unit coordinated an operation to disrupt the infrastructure associated with it.

2026-09-22
5 min read
0 views
certi.news Editorial Team
Microsoft Disrupts EvilTokens Infrastructure After More Than 12,000 Mailboxes Compromised Through Device Code Phishing

Microsoft revealed that the phishing-as-a-service platform EvilTokens had, since emerging in February 2026, become one of the most widely used phishing platforms after providing attackers with ready-made templates, automated operational infrastructure, and artificial intelligence capabilities for customizing messages and analyzing compromised mailboxes. According to the company, campaigns linked to the platform resulted in the compromise of more than 12,000 mailboxes across more than 10,000 organizations worldwide.

Microsoft said that its Digital Crimes Unit (DCU), in cooperation with partners, coordinated an operation to disrupt the infrastructure and operations used to run EvilTokens. Microsoft Threat Intelligence tracks the platform’s developer and operator under the name Storm-2992.

How Did EvilTokens Exploit Device Codes?

The platform primarily relied on abusing the device code authentication flow, a legitimate OAuth flow designed for devices with limited interfaces, such as smart TVs, printers, Teams devices, and conferencing systems. This flow displays a short code that the user enters in a browser on another device to complete sign-in.

In a phishing scenario, the attacker initiates the authentication request instead of the legitimate device and then presents the code to the user through a deceptive message. When the user enters the code into the official Microsoft portal, they grant authorization to the attacker’s session without revealing the password. If the user is already signed in, entering the code and confirming the request may be enough to complete authentication.

After obtaining the tokens, attackers can access email, create inbox rules that conceal messages, add new devices to maintain access, and use Microsoft Graph to map the organizational structure and permissions. In some cases, new devices were recorded as being created within ten minutes of the compromise, while email extraction or the creation of malicious rules was delayed for hours to reduce the chances of detection.

An Automated Platform for Phishing and Business Fraud

Storm-2992 sold EvilTokens through Telegram channels for $1,500 for the initial purchase and $500 per month to maintain access to the package and control panel, with additional fees for some tools. The panel allows users to choose the deployment method, templates, page language, code display style, CAPTCHA, artificial intelligence mode, and tracking of victims and stolen tokens.

The platform included 44 themes for convincing messages and pages, ranging from invoices and requests for proposals to file sharing, document-signing services, and password-expiration notifications. Attackers also used an intelligent assistant to compose messages suited to the victim’s role, then scanned mailboxes to find users in financial, executive, and administrative roles, as well as data such as bank transfers, invoices, and executive correspondence.

To evade email gateways and scanning tools, the campaigns relied on image links, multistage redirects, and HTML and PDF attachments, in addition to legitimate cloud services and infrastructure such as Vercel, Cloudflare Workers, and AWS Lambda. In a campaign observed by Microsoft during April 2026, the attackers created thousands of short-lived polling nodes to run dynamic backend logic and bypass signature-based detection.

What Matters to Defense Teams?

Microsoft recommends blocking the device code flow wherever possible, or restricting it through Conditional Access policies to the accounts and devices that genuinely need it. It also recommends using phishing-resistant authentication methods such as FIDO keys or passkeys through Microsoft Authenticator, enabling anti-phishing and Safe Links policies, and monitoring the creation of suspicious mailbox rules and high-risk sign-ins.

When token theft is suspected, the company says it is necessary to disable the device and revoke refresh tokens and sessions, noting that revoking refresh tokens alone may leave current access tokens active for up to an hour. Therefore, temporarily disabling the account may be necessary for immediate containment, despite its potential operational impact.

Why Does This News Matter?

The significance of EvilTokens does not lie in an entirely new phishing technique, but in turning the abuse of an existing flow into a scalable commercial service that combines AI-based customization, automation, token theft, and post-compromise movement. This shows that enabling multifactor authentication does not eliminate the risks of authorization-based phishing, because an attacker can target the authentication session itself. The recommendations in the source remain tied to the Microsoft Entra and Defender environments, and the disruption operation does not automatically mean that all campaigns or similar infrastructures have disappeared.

News source
Microsoft Security Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news