Part of a story covered by 14 sources: “Microsoft-led takedown disrupts EvilTokens, the AI-powered device-code phishing service behind 12,000+ inbox compromises” — merged summary and timeline →
Microsoft Disrupts EvilTokens Device Code Phishing Service
AI summary · grok-4.7
Microsoft seized 50 sites and disabled over 150 domains used by EvilTokens to phish Microsoft 365 accounts.
Microsoft disrupted EvilTokens, a phishing-as-a-service platform that used device-code phishing against Microsoft 365 accounts. The company seized 50 websites and disabled more than 150 domains in a coordinated effort. The action targets infrastructure used to phish cloud identities rather than a newly disclosed software flaw.
- EvilTokens is a device-code phishing-as-a-service platform
- Microsoft seized 50 websites during the disruption
- More than 150 associated domains were disabled
- The service targeted Microsoft 365 accounts
Full article
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.