Microsoft disrupts EvilTokens device-code phishing operation

Microsoft has disrupted EvilTokens, a commercial device-code phishing service linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide. The court-authorized action in the U.S. Eastern District of Virginia resulted in the seizure of 50 websites and the disabling of more than 150 domains used by the operation.
Microsoft tracked the developers and support operators as Storm-2992. Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs supported the action. Separately, the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial service.
How the device-code phishing flow worked
EvilTokens abused the OAuth 2.0 device authorization flow, a legitimate mechanism designed to connect devices to accounts. Phishing messages used 44 themes, including invoices, requests for proposals and shared files. Malicious links, PDF attachments or HTML files sent recipients through redirection chains to a page that generated a live device code.
The page displayed the code and directed the recipient to Microsoft’s genuine microsoft.com/devicelogin portal. A victim who entered the code completed an apparently normal sign-in flow. If necessary, the portal requested credentials and multi-factor authentication. The authorization server then issued access and refresh tokens to the attacker’s client, giving the attacker authenticated access under the victim’s identity.
This distinction is important: the victim did not necessarily disclose a password to the phishing page. Microsoft said that access could remain after a password reset if associated sessions and tokens were not revoked. Attackers could use the access to exfiltrate email, register new devices and create malicious inbox rules that concealed communications.
AI tools turned mailbox access into fraud preparation
At the centre of EvilTokens was an AI-style chatbot that examined compromised inboxes for trusted relationships, payment authorizations and sensitive responsibilities. It could summarize and translate messages, map organizational roles, identify finance-related threads and recommend people to impersonate. Microsoft said the platform could also draft messages that imitated trusted contacts.
TRM Labs described the service as combining account takeover, AI-driven mailbox analysis and fraud tooling in one offering. Sekoia reported that the Telegram-based phishing-as-a-service operation sold self-hosted templates and AI functions for business email compromise workflows. Its advertised products included a $600 B2B sender, a $1,500 Office 365 capture link and a $1,000 SMTP sender; continued access to the kit and control panel cost $500 per month.
Coinbase traced about $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, with more than 1,000 deposits from over 700 distinct crypto addresses. SpyCloud contributed recaptured phishing data involving 8,708 unique victim accounts across 6,585 corporate email domains in 79 countries.
What organizations should take from the disruption
The most affected activity was observed in the U.S., Canada, the U.K., Australia, India and France. Victims included organizations in wholesale distribution, construction, financial services, real estate, higher education and healthcare. The delivery chain also used fake CAPTCHA checks and high-reputation serverless platforms, including Vercel, Cloudflare Workers and AWS Lambda, to blend into ordinary enterprise cloud traffic.
Businesses should ensure that employees recognize unsolicited device-code prompts as a phishing risk, particularly when they originate from an email or attachment. After a suspected account compromise, incident teams need to revoke active sessions and tokens as well as reset passwords, then inspect inbox rules, newly registered devices and email access for signs of persistence or data exfiltration.

