www.microsoft.com 22 Sept 2026, 15:00 UTC

Microsoft Disrupts EvilTokens Phishing Platform After 12,000 Compromises

Microsoft Disrupts EvilTokens Phishing Platform After 12,000 Compromises
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Storm-2992

MICROSOFT says the EvilTokens phishing-as-a-service platform compromised more than 12,000 inboxes across over 10,000 organisations worldwide after emerging in February 2026. The service, attributed to the threat actor Storm-2992, used AI to tailor phishing messages, analyse compromised mailboxes and identify valuable targets.

Victims included organisations in wholesale distribution, construction, financial services, real estate, higher education and healthcare, with significant activity observed in the United States, Canada, the UK, Australia, India and France. Microsoft’s Digital Crimes Unit, working with partners, facilitated a coordinated disruption of infrastructure used to operate the service.

EvilTokens abused Microsoft’s legitimate device-code authentication flow. Attackers generated a live code and persuaded victims to enter it on the genuine `microsoft.com/devicelogin` site, unknowingly authorising the attacker’s session without revealing credentials. The stolen tokens enabled mailbox access, Microsoft Graph reconnaissance, data theft and malicious inbox rules that concealed activity. In some cases, attackers registered new devices to obtain a Primary Refresh Token (PRT) for longer-term persistence.

Campaigns used 44 lure themes, including invoices, password-expiry notices, shared files and RFPs, with redirects and hosting on services such as Vercel, Cloudflare Workers and AWS Lambda to evade detection. Microsoft recommends blocking device-code flow wherever possible; where it is required, organisations should restrict exceptions. Suspected compromises should be contained by disabling the account or device, revoking tokens, investigating inbox rules and following Microsoft’s compromised-account guidance.

View full article

Article by CyberSIXT