The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine
EvilTokens PhaaS kit uses AI and device-code phishing to bypass MFA, compromising 12,000+ corporate inboxes for payment fraud.
EvilTokens is a phishing-as-a-service (PhaaS) kit that has compromised over 12,000 inboxes at more than 10,000 organizations by exploiting Microsoft's device-code sign-in flow. The kit, operated by Storm-2992, uses AI to generate targeted lures and automate post-compromise reconnaissance for business email compromise (BEC). Once access is gained, attackers register new devices and create hidden inbox rules to maintain persistence and evade detection.
- EvilTokens is a PhaaS kit that uses device-code phishing to bypass MFA.
- The kit compromised over 12,000 inboxes at 10,000+ organizations.
- AI features help draft lures and map organizational structures for targeted fraud.
- Attackers register new devices and create hidden inbox rules for persistence.
Full article742 words · extracted from cybersecuritynews.com · click to collapse
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password.
The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in.
The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise.
Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide.
Affected sectors include finance, construction, healthcare and education. Microsoft saw the most victim activity in the United States, Canada, the United Kingdom, Australia, India and France.
.webp)
Earlier coverage of EvilTokens as a phishing service traced its rapid rise, while the new findings show how stolen access feeds further scams.
The Phishing Kit That Turned Microsoft’s Login Flow
Device code sign-in was designed for equipment that cannot easily display a full login form. A person enters its short code in a browser to approve access. EvilTokens reverses the trust: the attacker starts the request, then persuades the victim to complete it.
The kit creates a fresh code when the target opens the phishing page. It can copy the code to the clipboard and direct users to Microsoft’s genuine sign-in portal.
As device code phishing attacks have shown, checking that the final login page is real does not establish who initiated the request. While the victim signs in, an automated process repeatedly checks whether the approval has gone through.
Whether the person completes password and multifactor checks or confirms an existing session, the attacker’s waiting session receives the access tokens. The phishing site never needs the password.
Microsoft says operators can then read email, search for payment details and use compromised accounts to contact colleagues or outside partners.
The kit’s AI features help draft lures tailored to a person’s job and sift through captured mail for executives, finance staff and administrators. It can also map organizational relationships to guide the next move.
.webp)
That increases the value of a stolen session. Rather than sending a generic fake invoice, an attacker can study real conversations and write a request that fits an existing business relationship.
Earlier reporting on AI assisted mailbox targeting described this shift from simple account takeover toward more convincing payment fraud.
Evasion, Persistence and Defense
EvilTokens is sold to other criminals through Telegram, with a $1,500 initial price and a $500 monthly fee. Its panel offers 44 themes, redirect options and victim tracking. That packaged approach lets subscribers run campaigns without building every component themselves.
The operation can place deceptive links in images, use staged redirects and show fake verification checks before revealing the sign-in prompt. Microsoft observed thousands of short-lived automation nodes in April. These tactics make a single phishing address a poor guide to the wider operation.
Once inside, attackers may create inbox rules to hide messages or register new devices for longer-lasting access. In some cases, Microsoft saw device registration within 10 minutes of a breach. The risk resembles executive impersonation invoice schemes that rely on a plausible request reaching the right finance employee.
.webp)
Microsoft recommends blocking device code sign-in where it is not needed and narrowly limiting exceptions where it is. Organizations should train employees not to approve codes they did not request, watch for unusual sign-ins and new inbox rules, and independently verify payment requests.
If compromise is suspected, responders should revoke refresh tokens and investigate mailbox activity. Microsoft warns that existing access tokens may remain usable for up to an hour after standard session revocation, so temporarily disabling the account can provide immediate containment while checking registered devices and hidden mail rules.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.