securityonline.info 22 Sept 2026, 17:49 UTC

Microsoft Disrupts EvilTokens MFA Phishing Service Linked to 12,000 Inboxes

Microsoft Disrupts EvilTokens MFA Phishing Service Linked to 12,000 Inboxes
CyberSIXT Evidence Panel
Threat Actor
Storm-2992

MICROSOFT says it has disrupted EvilTokens, a phishing-as-a-service platform launched in February 2026 that used device-code phishing to bypass multi-factor authentication. Victims were persuaded to enter attacker-generated codes into legitimate Microsoft sign-in pages, granting criminals valid OAuth access and refresh tokens without exposing their passwords.

The platform’s built-in AI chatbot analysed compromised mailboxes, identified financial approval discussions and useful targets, and helped draft requests for urgent wire transfers. Attackers also used cloud services including Cloudflare Workers, AWS Lambda and Vercel to host landing pages and conceal traffic behind reputable domains.

Microsoft Threat Intelligence attributes the service’s development and operation, with moderate confidence, to Storm-2992. It says EvilTokens was sold through Telegram for $1,500 plus $500 per month and was linked to more than 12,000 compromised inboxes across over 10,000 organisations. Reported victims included healthcare, education, finance, construction and wholesale businesses, particularly in the US, Canada, UK, Australia, India and France.

Microsoft says attackers created hidden inbox rules and sometimes registered rogue devices to maintain access. The Metropolitan Police arrested two men, aged 32 and 38, in the UK on 11 September 2026; both were released on police bail.

Following a civil action in the Eastern District of Virginia, Microsoft says it seized 50 active websites and disabled more than 150 supporting domains, working with Cloudflare, OpenAI and other partners. Recommended measures include restricting device-code authentication, applying conditional-access controls, revoking active session tokens after compromise, and independently verifying payment changes.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline