MICROSOFT and public- and private-sector partners have disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts. Microsoft says the service, operated by the group it calls Storm-2992, supported sophisticated business email compromise campaigns that compromised more than 12,000 inboxes across over 10,000 organisations worldwide. The operation emerged in February and was sold through Telegram for $1,500 upfront and $500 a month in cryptocurrency.
EvilTokens automated device-code phishing: victims were taken to a malicious page that generated or displayed a device code before redirecting them to Microsoft’s legitimate device-login portal. By completing the normal authentication process, victims inadvertently authorised the attacker’s session. Once access was obtained, the platform’s AI tools analysed inboxes, identified valuable relationships and payment authorities, and helped plan further fraud.
Microsoft also observed attackers using Microsoft Graph to map organisational structures and sensitive permissions. SpyCloud identified 8,708 compromised accounts across 6,585 corporate email domains in 79 countries; its data indicated that the ten most active customers accounted for 60% of unique victims.
As part of US court-authorised legal action this month, Microsoft seized 50 websites used to operate the service and disabled more than 150 related domains. The UK Metropolitan Police Service arrested two men earlier in September over suspected connected offences; both were released on bail while the investigation continues. Microsoft recommends allowing device-code authentication only where necessary and blocking the flow where possible. SpyCloud’s Trevor Hilligoss warned that prolific operators may move to rival phishing services.