Microsoft dismantles AI-powered phishing platform EvilTokens

2 hours ago 5

Phishing has been a problem for decades. What’s new is that it now comes with a subscription tier and an AI content generator, and the people running it were apparently operating out of the UK until last week.

Microsoft’s Digital Crimes Unit announced on September 22 that it had dismantled the core infrastructure behind EvilTokens, a phishing-as-a-service platform the company tracks internally as Storm-2992. The operation compromised more than 12,000 Microsoft 365 inboxes across over 10,000 organizations globally before Microsoft and its partners shut it down.

Two UK administrators, aged 32 and 38, were arrested in coordination with Health-ISAC, cybersecurity firm SpyCloud, and local law enforcement. Both suspects were subsequently released on bail while investigations continue.

How EvilTokens actually worked

The clever part of EvilTokens was that it didn’t try to trick victims into handing over passwords. It exploited Microsoft’s own device authorization grant flow, the legitimate OAuth process that lets users authenticate on devices without keyboards, like smart TVs.

A victim would receive a phishing message directing them to a real Microsoft page and asking them to enter a device code. That code is genuine. The catch is that the code was generated by the attacker, not the victim’s own device. By entering it, the victim unknowingly handed the attacker a persistent OAuth token granting full access to their Microsoft 365 account.

MFA provided no protection against this method because the authentication itself was real. The malice was in the setup, not the login.

SpyCloud’s independent analysis found that EvilTokens had compromised 8,708 accounts spanning 6,585 domains across 79 countries.

A platform built for scale

EvilTokens launched on Telegram in mid-February 2026 and was first documented publicly by cybersecurity researchers at Sekoia in March of the same year. According to Huntress telemetry, device-code phishing attacks increased by 1,380% in the period following the platform’s emergence.

Subscriptions ran from $600 to $1,500, with additional add-ons available on top. For that price, customers got AI-generated phishing lures, automated tooling to execute business email compromise campaigns, and features that let attackers mimic the communication style of a compromised inbox to fool colleagues and partners into wiring money or sharing sensitive data.

What the takedown means going forward

The collaboration model matters here. No single company or agency has full visibility into a platform like EvilTokens. SpyCloud contributed victim and domain data. Health-ISAC flagged compromised healthcare organizations. UK law enforcement made the arrests.

Microsoft has previously acknowledged the device-code flow as an area of concern and has added conditional access policies that organizations can configure to restrict its use.

The two UK suspects remain free on bail. The investigation is ongoing, and whether the EvilTokens infrastructure stays dark or resurfaces in a different form will likely depend on how much of the operation extended beyond the two individuals who were arrested.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article