Microsoft Dismantles the EvilTokens AI Phishing Platform

EvilTokens AI phishing platform abusing OAuth device code flow to hijack Microsoft accounts

The password is no longer the main barrier: EvilTokens made users themselves confirm access for attackers on a genuine Microsoft page, then handed its clients working tokens. Over several months, the platform helped compromise more than 12,000 mailboxes across upward of 10,000 organizations worldwide. On September 22, Microsoft and its partners announced the disruption of EvilTokens’ infrastructure, detailed in Microsoft’s post on disrupting the AI chatbot built for cybercrime.

How Device Code Phishing Works

The attack was built around OAuth 2.0 Device Code, a mechanism for signing in on devices with inconvenient input, such as televisions, printers, and conferencing systems. The criminal requested a code for their own session, then convinced the victim to enter it on the official Microsoft page. A similar device-code authorization scheme had already been used in campaigns against Microsoft 365, disguised as messages about salaries and corporate benefits.

Once the code was confirmed, the attacker received a token and could work with the mailbox in the user’s name. Under this scheme, the criminal never needed a password at all, and multi-factor authentication did not stop the attack, since the victim was the one completing the standard verification. The problem is familiar from other session-hijacking schemes, though EvilTokens reached the tokens through the legitimate Device Code Flow rather than through a proxy sitting between the user and the site.

Why a Password Change Wasn’t Enough

A simple password change might not close off access either. As long as the stolen sessions and tokens remained valid, the attacker retained access to the mailbox. In some attacks, the criminals registered additional devices, created inbound mail rules to conceal correspondence, and used Microsoft Graph to quickly map the company’s structure and locate employees with valuable privileges.

An AI Assistant Built Into the Kit

Once the mailbox was seized, EvilTokens’ built-in AI assistant took over. The system scanned through thousands of emails, translated correspondence, and searched for invoices, bank transfers, executives, and employees authorized to move money. The AI also identified trusted business relationships, suggested suitable fraud scenarios, and drafted messages posing as people known to the victim.

A Commercial Cybercrime Service

EvilTokens turned this entire chain into a commercial service. Microsoft tracks the development group under the designation Storm-2992. Access was sold through Telegram for $1,500 upfront and a further $500 a month. The panel offered dozens of phishing templates, distribution tools, page configuration, and further tools for working with hijacked accounts. Microsoft also found signs that developers built a significant portion of the platform itself with the help of AI. SpyCloud, which contributed recaptured phished data to the operation, published its own account of disrupting the EvilTokens PhaaS platform.

The Takedown

To halt the service, Microsoft and its partners carried out an operation that brought 50 sites under their control and disabled more than 150 associated domains. In the United Kingdom, police arrested two men, aged 32 and 38, on September 11, on suspicion of involvement in running EvilTokens. After their digital equipment was seized, both were released on bail pending the investigation.

Data gathered by SpyCloud linked EvilTokens to at least 8,708 unique hijacked accounts across 6,585 corporate email domains in 79 countries. The earliest records discovered date to February 18, 2026. Microsoft, drawing on its own attack data, estimates the overall scale higher still: more than 12,000 mailboxes across upward of 10,000 organizations.

What Organizations Should Do

Microsoft advises disabling Device Code Flow entirely wherever employees and equipment do not use it, and limiting any necessary exceptions to specific device accounts. If compromise is suspected, a single password reset is not enough. Administrators need to revoke active tokens and sessions, and check for newly registered devices, mailbox rules, and unusual Microsoft Graph activity.

A Technique That Predates This Takedown

The mass spread of this technique began long before the current operation. In the spring, the number of Device Code attacks grew 37-fold, and ready-made phishing-as-a-service kits sharply lowered the barrier to entry for less experienced criminals.

By summer, EvilTokens’ infrastructure had grown even more sophisticated. A related kit, ARToken, learned to conceal its attack behind legitimate Microsoft resources, exploit genuine business relationships, and manage correspondence after an account had already been seized.

The core problem extends well beyond EvilTokens itself. A password and a second factor protect the moment of sign-in, but an active token represents an already-confirmed session. Consequently, once that token is stolen, two-factor authentication alone does not restore control over the account.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply