Microsoft-led takedown disrupts EvilTokens, the AI-powered device-code phishing service behind 12,000+ inbox compromises
Microsoft and partners seized EvilTokens infrastructure and UK police arrested two suspects after the Storm-2992 phishing-as-a-service used OAuth device-code phishing and an AI chatbot to compromise 12,000+ inboxes at 10,000+ organizations.
Microsoft's Digital Crimes Unit, acting on an order from the U.S. District Court for the Eastern District of Virginia and with partners including Health-ISAC (a co-plaintiff), Cloudflare, Coinbase, and OpenAI (SecurityWeek also credits SpyCloud), dismantled EvilTokens, a Telegram-marketed phishing-as-a-service platform Microsoft tracks to actor Storm-2992. Active since February 2026, EvilTokens compromised more than 12,000 email inboxes at over 10,000 organizations worldwide, concentrated in the US, Canada, UK, Australia, India, and France per Ars Technica, with GBHackers citing finance, healthcare, and education targets. The kit abused the OAuth 2.0 device-code flow so victims entered codes at Microsoft's legitimate login page, bypassing MFA and handing over session tokens without passwords; access tokens granted persistence that could survive a password reset, via hidden inbox rules and new device registrations, while Microsoft Graph reconnaissance mapped organizations for lateral movement. Delivery used 44 lure themes (invoices, RFPs, shared files) and thousands of short-lived Node.js polling nodes to evade detection. An AI chatbot analyzed compromised inboxes, identified high-value targets and payment contacts, summarized and translated mail, and drafted impersonation emails for business email compromise. Pricing was a $1,500 signup plus $500 per month (The Hacker News reports products ranged from $600 to $1,500 plus the monthly fee); Coinbase traced about $1.1 million in Tron revenue from October 2025 to June 2026 across more than 700 crypto addresses. Microsoft seized 50 websites and disabled more than 150 related domains (Security Affairs puts the figure at over 175). London's Metropolitan Police arrested two suspected administrators, ages 32 and 38, later released on bail; the arrest date is reported as September 11, 2026 by The Hacker News and Help Net Security, but as September 18 by The Register. Microsoft recommends blocking the device code flow where possible and has published Defender detection and hunting guidance plus mail-flow hardening steps.
- EvilTokens compromised more than 12,000 email inboxes at over 10,000 organizations worldwide since February 2026.
- Microsoft tracks the operators as Storm-2992; targets concentrated in the US, Canada, UK, Australia, India, and France, with finance, healthcare, and education sectors cited.
- The kit abused the OAuth 2.0 device-code authentication flow so victims entered codes at Microsoft's legitimate login page, bypassing MFA and exposing tokens without collecting passwords.
- Stolen tokens enabled persistence via malicious inbox rules and new device registration; token access could survive a password reset, and Microsoft Graph reconnaissance mapped organizations for lateral movement.
- An AI chatbot analyzed inboxes, identified high-value targets and payment contacts, summarized and translated mail, and drafted impersonation emails for business email compromise.
- Delivery used 44 lure themes (invoices, RFPs, shared files) with malicious URLs, PDFs, and HTML files, plus thousands of short-lived Node.js polling nodes to evade detection.
- Pricing: $1,500 initial fee plus $500 monthly subscription (The Hacker News reports a $600–$1,500 product range); Coinbase traced about $1.1 million in Tron revenue from October 2025 to June 2026 across 700+ crypto addresses.
- Under a US court order (Eastern District of Virginia), Microsoft seized 50 websites and disabled more than 150 domains; Security Affairs reports over 175 domains disabled.
Coverage timelineoldest first · each row is one article
- · 4d agoUnmasking EvilTokens: Getting to the root of device code phishing
Microsoft Security Blog· 76
Microsoft details the EvilTokens/Storm-2992 device-code phishing operation and shares Defender detections after disrupting the AI-powered platform.
- · 4d agoEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
BleepingComputer· 73
Microsoft-led disruption hits EvilTokens PhaaS after it compromised 12,000+ accounts at 10,000+ organizations; two UK suspects arrested.
- · 4d ago