Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
AI Summary
Microsoft, in collaboration with multiple public and private partners, disrupted the EvilTokens phishing-as-a-service (PhaaS) platform, which leveraged AI to automate and scale business email compromise (BEC) attacks. The service abused OAuth 2.0 device authorization flows to gain persistent access to Microsoft accounts without stealing passwords, using social engineering to trick users into entering device codes on legitimate Microsoft login pages. EvilTokens offered AI-powered tools to analyze compromised inboxes, identify financial workflows, and draft convincing phishing emails, enabling even low-skill attackers to conduct sophisticated fraud. The operation led to the seizure of 50 websites, takedown of 150 domains, and the arrest of two individuals, with evidence linking the service to over 12,000 compromised inboxes across 10,000 organizations worldwide.
AI-extracted · verify before operational use
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | microsoft[.]com/devicelogin | Details → |
| GitHub User | eviltokensadmin | Details → |
| GitHub User | eviltokensadmins | Details → |
| GitHub User | EvilTokenscontact | Details → |
| GitHub User | eviltokens_bot | Details → |
| GitHub User | EvilTokensStorebot | Details → |
| GitHub Repo | EvilTokensChannel | Details → |
| GitHub Repo | https://t.me/+wNBoU1Gl2mRiYmU0 | Details → |