hacker-news · Crawled Sep 22, 2026

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

8 IoCs
Read original article ↗

AI Summary

Microsoft, in collaboration with multiple public and private partners, disrupted the EvilTokens phishing-as-a-service (PhaaS) platform, which leveraged AI to automate and scale business email compromise (BEC) attacks. The service abused OAuth 2.0 device authorization flows to gain persistent access to Microsoft accounts without stealing passwords, using social engineering to trick users into entering device codes on legitimate Microsoft login pages. EvilTokens offered AI-powered tools to analyze compromised inboxes, identify financial workflows, and draft convincing phishing emails, enabling even low-skill attackers to conduct sophisticated fraud. The operation led to the seizure of 50 websites, takedown of 150 domains, and the arrest of two individuals, with evidence linking the service to over 12,000 compromised inboxes across 10,000 organizations worldwide.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
Domain microsoft[.]com/devicelogin Details →
GitHub User eviltokensadmin Details →
GitHub User eviltokensadmins Details →
GitHub User EvilTokenscontact Details →
GitHub User eviltokens_bot Details →
GitHub User EvilTokensStorebot Details →
GitHub Repo EvilTokensChannel Details →
GitHub Repo https://t.me/+wNBoU1Gl2mRiYmU0 Details →