{"id":3063,"date":"2026-09-22T18:05:57","date_gmt":"2026-09-22T18:05:57","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3063"},"modified":"2026-09-22T18:05:57","modified_gmt":"2026-09-22T18:05:57","slug":"microsoft-takes-down-eviltokens-device-code-phishing-service-tied-to-12000-inbox-compromises","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3063","title":{"rendered":"Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjyLwFD0zZ8OEPo1dkZ0Tz87aOYoCklNQODjV4MMj90RNo6hRh9rGuJmFQBx5igj0gT1CabBEkSERWh7w_VdfZWpfs6BaJmEMc0KN9nIJXtxpYUINf1alSW9K2whcD9MXF4CaCWAKLJRJQlI51aqGtdpbpbdiX7WjpjTUxDvNgb0gc4qtmuZLat8-lGSFhu\/s1700-nu-rw-lo-l85-e365\/ms-eviltokens.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft on Tuesday <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2026\/09\/22\/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime\/\" target=\"_blank\">announced<\/a> the takedown of the <strong>EvilTokens<\/strong> device code phishing service that it said used artificial intelligence (AI) \u00abat every step of the attack chain.\u00bb<\/p>\n<p>The action, carried out with <a href=\"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/customer-security-trust\/digital-crimes-unit\/notice-of-pleadings\/eviltokens\/\" target=\"_blank\">authorization<\/a> from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside <a href=\"https:\/\/blog.cloudflare.com\/threat-intelligence\/research\/report\/cloudflare-participates-in-global-operation-to-disrupt-eviltokens-phishing-as-a-service\/\" target=\"_blank\">Cloudflare<\/a>, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Microsoft is tracking the threat actors behind the development and support of EvilTokens as <strong><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/22\/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing\/\" target=\"_blank\">Storm-2992<\/a><\/strong>.<\/p>\n<p>In tandem, the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial operation. The tech giant described EvilTokens as a \u00abpowerful cybercrime platform\u00bb that used AI to compromise email accounts and design roadmaps for financial fraud and scams.<\/p>\n<p>\u00abWhile EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim&#8217;s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,\u00bb Steven Masada, associate general counsel and general manager at Microsoft&#8217;s Digital Crimes Unit, said.<\/p>\n<p>\u00abThe platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.\u00bb<\/p>\n<p>EvilTokens was first documented by Huntress in March 2026 as a phishing-as-a-service (PhaaS) platform that <a href=\"https:\/\/www.netcraft.com\/blog\/eviltokens-and-oauth-abuse\" target=\"_blank\">abused<\/a> the <a href=\"https:\/\/www.welivesecurity.com\/en\/cybercrime\/eviltokens-phishing-doesnt-steal-password\/\" target=\"_blank\">OAuth 2.0 device authorization flow<\/a> to give attackers authenticated sessions with victim accounts without having to supply any credentials at their end.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The stolen tokens are abused for email exfiltration and persistence, often by setting malicious inbox rules that conceal communications. In some cases, the tokens have also been abused to grant new devices access to a victim&#8217;s inbox, thereby giving attackers an alternative pathway to maintaining long-term access.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The malicious lure, typically delivered via phishing attacks, shows the user a device code for the service that the threat actor wishes to access. The victim is then prompted to enter this code at the legitimate verification URL (e.g., microsoft.com\/devicelogin) during the sign-in process.<\/p>\n<p>Once the code is supplied, the authorization server issues access and refresh tokens to the attacker&#8217;s client, granting them ongoing access under the victim&#8217;s identity.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcPNqYrCGDs6W1ILBqR599NctD5iwbHzQJvfTRSMaJ91W3plXgWr89F92lJ7UJJGHwd9LiFX5de8MDupfbhgyV5YS7Od1OpJgiZB3z_uD6xoNwfxHZHgvVJHiX7i0dnWA6APKrt4iudIqIm-mt199J-ZoIF50YQ3ozkWe7c7eUOClZy-F_BYWEjK4KvuZz\/s1700-nu-rw-lo-l85-e365\/ms-1.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcPNqYrCGDs6W1ILBqR599NctD5iwbHzQJvfTRSMaJ91W3plXgWr89F92lJ7UJJGHwd9LiFX5de8MDupfbhgyV5YS7Od1OpJgiZB3z_uD6xoNwfxHZHgvVJHiX7i0dnWA6APKrt4iudIqIm-mt199J-ZoIF50YQ3ozkWe7c7eUOClZy-F_BYWEjK4KvuZz\/s1700-nu-rw-lo-l85-e365\/ms-1.png\" alt=\"\" border=\"0\" data-original-height=\"1440\" data-original-width=\"2560\"\/><\/a><\/div>\n<p>\u00abEvilTokens packaged account takeover, AI-driven mailbox analysis, and fraud tooling into a single commercial service, lowering the expertise once needed to run business email compromise and invoice fraud at scale,\u00bb TRM Labs <a href=\"https:\/\/www.trmlabs.com\/resources\/blog\/trm-labs-supports-microsofts-disruption-of-eviltokens-an-ai-powered-cybercrime-service\" target=\"_blank\">said<\/a>.<\/p>\n<p>In a report published in late March 2026, Sekoia characterized EvilTokens as a turnkey solution sold under a PhaaS model on Telegram since mid-February, offering customers a plethora of self-hosted phishing templates and AI-powered features to automate business email compromise (BEC) workflows, such as analyzing harvested emails, identifying finance-related email threads, and drafting BEC emails.<\/p>\n<p>Some of the Telegram accounts, channels, and groups linked to EvilTokens are below &#8211;<\/p>\n<ul>\n<li>EvilTokens Admin &#8211; @eviltokensadmin, @eviltokensadmins, and @EvilTokenscontact (Backup)<\/li>\n<li>EvilTokens Store &#8211; @EvilTokens_bot and @EvilTokensStorebot<\/li>\n<li>Public channels &#8211; @EvilTokensChannel <\/li>\n<li>Telegram group &#8211; https:\/\/t.me\/+wNBoU1Gl2mRiYmU0<\/li>\n<\/ul>\n<p>Other AI-related tools allowed its customers to summarize and translate emails, map organizational roles, identify trusted relationships, and recommend potential targets. The service also offered preset prompts to find wire-transfer discussions, identify an organization&#8217;s money movers, locate vendor invoices, and determine the best people to impersonate.<\/p>\n<p>\u00abEvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,\u00bb Microsoft said. \u00abCapabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.\u00bb<\/p>\n<p>The threat actor has been found to offer three different products &#8211;<\/p>\n<ul>\n<li>EvilTokens B2B sender, for $600.<\/li>\n<li>EvilTokens Office 365 capture link, for $1500.<\/li>\n<li>EvilTokens SMTP sender, for $1000<\/li>\n<\/ul>\n<p>\u00abThe &#8216;Office 365 capture link&#8217; corresponds to the device code phishing kit,\u00bb Sekoia explained in a follow-up report in April 2026. \u00abThe one-time fee of $1,500 grants affiliates lifetime access to the EvilTokens administration panel for viewing harvested Microsoft tokens. Affiliates must also pay a monthly licence fee of $500 to obtain the phishing page code and an active API key for backend integration and core device code phishing functionality.\u00bb<\/p>\n<p>The service also charges a monthly subscription fee of $500 for continued access to the kit and control panel. Besides offering a way to personalize lures and use AI to craft targeted phishing emails, EvilTokens also allows paying customers to access a whole suite of auxiliary tools, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender.<\/p>\n<p>Coinbase <a href=\"https:\/\/www.coinbase.com\/en-in\/blog\/taking-down-evil-tokens\" target=\"_blank\">said<\/a> it traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, adding that it identified more than 1,000 deposits to EvilTokens from over 700 distinct addresses across the crypto ecosystem.<\/p>\n<p>Attacks using EvilTokens revolve around sending deceptive emails that make use of 44 different themes, including invoices and requests for proposals (RFPs), or shared files. These messages contain malicious URLs, PDF attachments, and HTML files to activate the infection chain &#8211;<\/p>\n<ul>\n<li>Upon clicking a malicious link or attachment, redirect users to a web page running a background automation script.<\/li>\n<li>The script interacts with the Microsoft identity provider in real time to generate a live device code.<\/li>\n<li>Display the code on the user&#8217;s screen with a \u00abCopy Code\u00bb button along with a \u00abContinue\u00bb or \u00abContinue with Microsoft\u00bb button that, when clicked, takes the victim to the official microsoft.com\/devicelogin portal.<\/li>\n<li>The user pastes the code on the real Microsoft site.<\/li>\n<li>If the user does not have an active Microsoft session, they are prompted to enter their credentials and multi-factor authentication (MFA) code.<\/li>\n<li>The threat actor&#8217;s session is authenticated, allowing them to register new devices, create malicious inbox rules, or exfiltrate sensitive email data.<\/li>\n<\/ul>\n<p>Simultaneously, EvilTokens employs a multi-stage delivery pipeline to bypass traditional email gateways and endpoint security through fake CAPTCHA checks and redirection chains that make use of high-reputation \u00abserverless\u00bb platforms like Vercel, Cloudflare Workers, and AWS Lambda to blend in with legitimate enterprise cloud traffic and sidestep domain-blocklist triggers.<\/p>\n<p>Statistics shared by Microsoft show that EvilTokens has been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, indicating the service had gained widespread traction among threat actors in a short span of time.<\/p>\n<p>The highest concentrations of victim activity have been observed in the U.S., Canada, the U.K., Australia, India, and France. Targeted organizations include wholesale distribution, construction, financial services, real estate, higher education, and healthcare.<\/p>\n<p>Microsoft said it worked with other partners to seize 50 websites used to operate the service and disable over 150 additional domains associated with its supporting infrastructure. <\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abEvilTokens helped criminals gain access to email accounts by tricking victims into entering an authentication code on Microsoft&#8217;s legitimate sign-in page. By completing the normal authentication sign-in process, victims unknowingly gave criminals access to their email accounts without revealing their passwords,\u00bb Microsoft explained. \u00abThat access could persist even after a password reset if the associated sessions and tokens were not also revoked.\u00bb<\/p>\n<p>What&#8217;s more, evidence points to large portions of the toolkit developed using AI assistance (aka vibe coded), signaling the technology&#8217;s ability to lower skill barriers and help aspiring cybercriminals develop advanced toolkits and help perpetrate fraud at scale. <\/p>\n<p>\u00abEvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation,\u00bb Masada added.<\/p>\n<p>SpyCloud, which was one of the private sector partners, <a href=\"https:\/\/spycloud.com\/blog\/disrupting-the-eviltokens-phaas-platform\/\" target=\"_blank\">said<\/a> it supported the disruption action by sharing recaptured phished data that included 8,708 unique victim accounts compromised by EvilTokens. These accounts span 6,585 unique corporate email domains located across 79 countries. The earliest captures date back to February 18, 2026.<\/p>\n<p>\u00abEvilTokens used AI to make the hard parts easy: reading compromised mailboxes in more than twenty languages to find the conversations worth hijacking, and drafting the impersonation mail that follows,\u00bb Trevor Hilligoss, SpyCloud&#8217;s Chief Investigations Officer, said in a statement. \u00abThose were the parts of business email compromise that used to require human involvement, and that scaled with the skill of the criminal; EvilTokens made them available to anyone for $500 a month.\u00bb<\/p>\n<p>\u00abFifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time. EvilTokens isn&#8217;t the only phishing-as-a-service platform deserving of a disruption, but its place as the first to implement device code phishing at scale makes this a meaningful disruption by any measure.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) \u00abat every step of the attack chain.\u00bb The action, carried&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3064,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[173,2098,3505,3506,147,390,572,437,343],"class_list":["post-3063","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-compromises","tag-devicecode","tag-eviltokens","tag-inbox","tag-microsoft","tag-phishing","tag-service","tag-takes","tag-tied"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3063"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3063\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3064"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}