Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

The Hacker News by The Hacker News
September 22, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”

The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Microsoft is tracking the threat actors behind the development and support of EvilTokens as Storm-2992.

In tandem, the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial operation. The tech giant described EvilTokens as a “powerful cybercrime platform” that used AI to compromise email accounts and design roadmaps for financial fraud and scams.

“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Steven Masada, associate general counsel and general manager at Microsoft’s Digital Crimes Unit, said.

“The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”

EvilTokens was first documented by Huntress in March 2026 as a phishing-as-a-service (PhaaS) platform that abused the OAuth 2.0 device authorization flow to give attackers authenticated sessions with victim accounts without having to supply any credentials at their end.

The stolen tokens are abused for email exfiltration and persistence, often by setting malicious inbox rules that conceal communications. In some cases, the tokens have also been abused to grant new devices access to a victim’s inbox, thereby giving attackers an alternative pathway to maintaining long-term access.

The malicious lure, typically delivered via phishing attacks, shows the user a device code for the service that the threat actor wishes to access. The victim is then prompted to enter this code at the legitimate verification URL (e.g., microsoft.com/devicelogin) during the sign-in process.

Once the code is supplied, the authorization server issues access and refresh tokens to the attacker’s client, granting them ongoing access under the victim’s identity.

“EvilTokens packaged account takeover, AI-driven mailbox analysis, and fraud tooling into a single commercial service, lowering the expertise once needed to run business email compromise and invoice fraud at scale,” TRM Labs said.

In a report published in late March 2026, Sekoia characterized EvilTokens as a turnkey solution sold under a PhaaS model on Telegram since mid-February, offering customers a plethora of self-hosted phishing templates and AI-powered features to automate business email compromise (BEC) workflows, such as analyzing harvested emails, identifying finance-related email threads, and drafting BEC emails.

Some of the Telegram accounts, channels, and groups linked to EvilTokens are below –

  • EvilTokens Admin – @eviltokensadmin, @eviltokensadmins, and @EvilTokenscontact (Backup)
  • EvilTokens Store – @EvilTokens_bot and @EvilTokensStorebot
  • Public channels – @EvilTokensChannel 
  • Telegram group – https://t.me/+wNBoU1Gl2mRiYmU0

Other AI-related tools allowed its customers to summarize and translate emails, map organizational roles, identify trusted relationships, and recommend potential targets. The service also offered preset prompts to find wire-transfer discussions, identify an organization’s money movers, locate vendor invoices, and determine the best people to impersonate.

“EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,” Microsoft said. “Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.”

The threat actor has been found to offer three different products –

  • EvilTokens B2B sender, for $600.
  • EvilTokens Office 365 capture link, for $1500.
  • EvilTokens SMTP sender, for $1000

“The ‘Office 365 capture link’ corresponds to the device code phishing kit,” Sekoia explained in a follow-up report in April 2026. “The one-time fee of $1,500 grants affiliates lifetime access to the EvilTokens administration panel for viewing harvested Microsoft tokens. Affiliates must also pay a monthly licence fee of $500 to obtain the phishing page code and an active API key for backend integration and core device code phishing functionality.”

The service also charges a monthly subscription fee of $500 for continued access to the kit and control panel. Besides offering a way to personalize lures and use AI to craft targeted phishing emails, EvilTokens also allows paying customers to access a whole suite of auxiliary tools, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender.

Coinbase said it traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, adding that it identified more than 1,000 deposits to EvilTokens from over 700 distinct addresses across the crypto ecosystem.

Attacks using EvilTokens revolve around sending deceptive emails that make use of 44 different themes, including invoices and requests for proposals (RFPs), or shared files. These messages contain malicious URLs, PDF attachments, and HTML files to activate the infection chain –

  • Upon clicking a malicious link or attachment, redirect users to a web page running a background automation script.
  • The script interacts with the Microsoft identity provider in real time to generate a live device code.
  • Display the code on the user’s screen with a “Copy Code” button along with a “Continue” or “Continue with Microsoft” button that, when clicked, takes the victim to the official microsoft.com/devicelogin portal.
  • The user pastes the code on the real Microsoft site.
  • If the user does not have an active Microsoft session, they are prompted to enter their credentials and multi-factor authentication (MFA) code.
  • The threat actor’s session is authenticated, allowing them to register new devices, create malicious inbox rules, or exfiltrate sensitive email data.

Simultaneously, EvilTokens employs a multi-stage delivery pipeline to bypass traditional email gateways and endpoint security through fake CAPTCHA checks and redirection chains that make use of high-reputation “serverless” platforms like Vercel, Cloudflare Workers, and AWS Lambda to blend in with legitimate enterprise cloud traffic and sidestep domain-blocklist triggers.

Statistics shared by Microsoft show that EvilTokens has been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, indicating the service had gained widespread traction among threat actors in a short span of time.

The highest concentrations of victim activity have been observed in the U.S., Canada, the U.K., Australia, India, and France. Targeted organizations include wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

Microsoft said it worked with other partners to seize 50 websites used to operate the service and disable over 150 additional domains associated with its supporting infrastructure. 

“EvilTokens helped criminals gain access to email accounts by tricking victims into entering an authentication code on Microsoft’s legitimate sign-in page. By completing the normal authentication sign-in process, victims unknowingly gave criminals access to their email accounts without revealing their passwords,” Microsoft explained. “That access could persist even after a password reset if the associated sessions and tokens were not also revoked.”

What’s more, evidence points to large portions of the toolkit developed using AI assistance (aka vibe coded), signaling the technology’s ability to lower skill barriers and help aspiring cybercriminals develop advanced toolkits and help perpetrate fraud at scale. 

“EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation,” Masada added.

SpyCloud, which was one of the private sector partners, said it supported the disruption action by sharing recaptured phished data that included 8,708 unique victim accounts compromised by EvilTokens. These accounts span 6,585 unique corporate email domains located across 79 countries. The earliest captures date back to February 18, 2026.

“EvilTokens used AI to make the hard parts easy: reading compromised mailboxes in more than twenty languages to find the conversations worth hijacking, and drafting the impersonation mail that follows,” Trevor Hilligoss, SpyCloud’s Chief Investigations Officer, said in a statement. “Those were the parts of business email compromise that used to require human involvement, and that scaled with the skill of the criminal; EvilTokens made them available to anyone for $500 a month.”

“Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time. EvilTokens isn’t the only phishing-as-a-service platform deserving of a disruption, but its place as the first to implement device code phishing at scale makes this a meaningful disruption by any measure.”



Source link

The Hacker News

The Hacker News

Next Post

Throo Takes Its 0% Commission Model Beyond New York City to Denver

Recommended.

UK government plans to ramp up sovereign computer capacity | Computer Weekly

UK government plans to ramp up sovereign computer capacity | Computer Weekly

July 17, 2025
Сеть в 2030 году: WBBA официально запускает AI-Net, глобально авторитетную сертификацию передачи данных

Сеть в 2030 году: WBBA официально запускает AI-Net, глобально авторитетную сертификацию передачи данных

July 16, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026
CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

CES 2026: 15 New Laptops That Deliver Cutting-Edge AI, Innovative Form Factors

January 8, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio