Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts
EvilTokens PaaS hijacks device-code auth to steal tokens and enable BEC at scale, compromising 12,000+ inboxes across 10,000+ organizations.
Microsoft warns that the EvilTokens phishing-as-a-service platform has compromised over 12,000 email inboxes across 10,000+ organizations since February 2026. The platform, linked to threat actor Storm-2992, industrializes device-code authentication hijacking for large-scale token theft and business email compromise. EvilTokens uses AI to generate tailored lures and sophisticated infrastructure to evade detection.
- EvilTokens PaaS compromises 12,000+ inboxes across 10,000+ organizations.
- Exploits OAuth device-code flow for token theft and BEC.
- Automated kit with AI-lure generation and stealthy infrastructure.
- Storm-2992 campaigns target finance, healthcare, and education globally.
- Microsoft recommends blocking device-code auth and monitoring for anomalous sign-ins.
Full article893 words · extracted from gbhackers.com · click to collapse
Microsoft has warned that the EvilTokens phishing-as-a-service platform has become a major driver of AI-enabled device-code phishing, compromising more than 12,000 email inboxes across over 10,000 organizations worldwide since emerging in February 2026.
The operation, linked to the threat actor Microsoft tracks as Storm-2992, industrializes token theft, mailbox reconnaissance, and business email compromise at scale
Instead of stealing a victim’s password directly, attackers initiate a device-code authentication session and socially engineer the target into entering an attacker-generated code at Microsoft’s legitimate device-login portal.
The victim may complete password and MFA prompts on a real Microsoft page, but the approval authorizes the adversary’s session and delivers valid access tokens to the attacker.
The technique is particularly dangerous because it turns MFA into part of the compromise path rather than bypassing it through a conventional credential-harvesting page.
EvilTokens improves the success rate through on-demand code generation: the 15-minute device-code validity window starts only after a target interacts with the phishing link, eliminating a major limitation of earlier static-code campaigns.
Microsoft observed the kit automatically copying device codes to victims’ clipboards, further reducing friction during the malicious authentication flow.
Microsoft’s April analysis described a highly automated campaign infrastructure that used short-lived Node.js polling nodes hosted through services such as Railway.
The backend dynamically generated authentication codes, monitored the victim’s approval status every three to five seconds, validated stolen tokens, and supported follow-on operations.
The use of serverless and legitimate cloud services makes simple reputation-based blocking less effective, as malicious traffic can blend into routine enterprise web activity.
Storm-2992 marketed EvilTokens through Telegram channels, offering subscribers a customizable control panel with phishing templates, attachment files, hosting options, redirect logic, CAPTCHA-based filtering, victim tracking, and token-management functions.
The service reportedly included 44 lure themes covering invoices, requests for proposals, document-sharing notifications, e-signature requests, voicemail messages, password-expiration notices, and cloud-service alerts.
EvilTokens phish kits are sold at $1,500 USD for initial purchase, with a monthly subscription fee of $500 for continued access to the kit and control panel.
AI-assisted features let operators tailor messages to a target’s role and create more convincing, business-focused lures.

The post-compromise capability is what elevates EvilTokens from a phishing kit into a BEC-enablement platform.
Once a token is captured, operators can search compromised mailboxes for financial discussions, wire-transfer details, pending invoices, executive correspondence, and contacts suitable for internal or supplier-targeted follow-on phishing.
EvilTokens AI Phishing
Microsoft also observed Microsoft Graph reconnaissance used to map organizational structures and permissions, helping attackers identify high-value financial, executive, and administrative users.
Microsoft observed that, EvilTokens abuses the OAuth device code authentication flow, a legitimate sign-in mechanism intended for devices with limited interfaces such as smart TVs, printers, and conferencing hardware.
In some incidents, attackers registered new devices shortly after compromise to obtain longer-lived access through a Primary Refresh Token.

In others, they delayed their actions, creating malicious inbox rules hours later to hide communications, redirect messages, or persist quietly while exfiltrating email data.
This delayed activity can complicate incident response because revoking refresh tokens may not immediately invalidate all existing access tokens.
Microsoft recommends temporarily deactivating a compromised account during containment when hands-on adversary activity is suspected.
The campaign has affected organizations in sectors including financial services, healthcare, construction, higher education, real estate, and wholesale distribution.
Microsoft observed significant victim activity in the United States, Canada, the United Kingdom, Australia, India, and France.
The company’s Digital Crimes Unit has coordinated with partners to disrupt infrastructure supporting the EvilTokens operation.
A typical EvilTokens intrusion begins with a high-pressure email carrying a malicious URL, PDF attachment, or HTML file.
The victim is routed through layered redirects often involving compromised sites or trusted serverless platforms such as Vercel, Cloudflare Workers, and AWS Lambda before landing on a fake document or verification page.
The page generates a live device code in real time and directs the user to microsoft.com/devicelogin. Because the destination is a legitimate Microsoft domain, the user may incorrectly assume the workflow is safe.
When the victim enters the displayed code and approves the sign-in, the attacker’s polling infrastructure receives a success response and gains access to valid account tokens.
Organizations should block device-code authentication wherever it is not operationally necessary and restrict exceptions to explicitly approved device accounts.
Microsoft also recommends enforcing Conditional Access policies, enabling anti-phishing protections and Safe Links in Defender for Office 365, and increasing the advanced phishing threshold to improve detection of sophisticated lures.
Security teams should monitor for anomalous device-code sign-ins, authentication attempts involving error code 50199 followed by a successful login, suspicious device registrations, unusual Microsoft Graph mailbox access, and newly created inbox rules.
Microsoft’s hunting guidance also highlights suspicious sign-ins from infrastructure associated with the campaign, including observed Railway and hosting-provider IP ranges.
Defenders should treat unexpected requests to enter device codes especially those delivered through email attachments, shared-document notifications, or external senders as high-risk.
A legitimate Microsoft login page does not validate the trustworthiness of the workflow that brought a user there.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.