securityaffairs.com 23 Sept 2026, 11:00 UTC

Microsoft Dismantles EvilTokens Phishing Service Behind 12,000 Breaches

Microsoft Dismantles EvilTokens Phishing Service Behind 12,000 Breaches
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Storm-2992

MICROSOFT , Coinbase and law-enforcement partners have dismantled EvilTokens, a phishing-as-a-service platform that Microsoft attributes to the Storm-2992 group. The service, which appeared in February 2026 and was advertised through Telegram, reportedly compromised more than 12,000 inboxes across over 10,000 organisations. It cost $1,500 upfront and $500 a month, with extra tools available for additional fees.

Its control panel offered 44 phishing themes, campaign and domain management, victim tracking and stolen-token handling, while AI generated targeted messages and analysed compromised mailboxes to identify payment controllers and other valuable accounts.

The operation centred on device-code phishing, which abuses a legitimate Microsoft sign-in process designed for devices such as smart TVs. Victims were directed to convincing Microsoft or DocuSign-style pages, often presented as invoices or shared documents, and told to enter a code on Microsoft’s genuine website. This authorised an attacker’s session without exposing the victim’s password or triggering their own MFA approval.

Attackers could then register devices in Entra ID, create hidden inbox rules and impersonate finance staff, suppliers or executives in payment conversations. Microsoft also reported Graph reconnaissance to map organisations and permissions, enabling potential continued access while tokens remained valid.

Microsoft’s Digital Crimes Unit seized 50 websites and disabled more than 175 related domains. Coinbase traced about $1.1m in proceeds across four Tron addresses, involving more than 1,000 deposits from over 700 wallets. The investigation led to the arrest of the alleged operator by London’s Metropolitan Police on 11 September, with devices seized for examination.

Defenders should treat unsolicited device-code requests as suspicious, verify payment changes through a known telephone number and consider passkeys or hardware security keys where available.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline