Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft, in collaboration with partners, successfully disrupted EvilTokens, a sophisticated phishing-as-a-service (PhaaS) platform that facilitated large-scale business email compromise (BEC) attacks targeting Microsoft 365 accounts. The platform utilized AI to automate device code phishing, a technique that bypassed traditional security measures by leveraging legitimate Microsoft authentication processes. The operation resulted in the seizure of 50 websites and disabling of 150 domains, alongside arrests of two men linked to the campaign. The disruption exposed a significant threat landscape, with a substantial number of high-volume operators likely migrating to competing PhaaS services.
Microsoft, alongside several partners, successfully disrupted EvilTokens, a phishing-as-a-service (PhaaS) platform that facilitated large-scale business email compromise (BEC) attacks targeting Microsoft 365 accounts. The platform utilized AI to automate device code phishing, a technique that bypassed traditional security measures by leveraging legitimate Microsoft authentication processes. The operation resulted in the seizure of 50 websites and disabling of 150 domains, alongside arrests of two men linked to the campaign.
EvilTokens emerged in February and rapidly expanded over the spring and summer, selling its services through Telegram for $1,500 upfront, plus $500 per month in cryptocurrency. The platform’s key capability was device code phishing – abusing Microsoft’s legitimate device authentication process. When a victim clicked on a phishing lure, EvilTokens initiated Microsoft’s device authentication process, leading them to a malicious webpage that generated or displayed the device code before redirecting them to the legitimate Microsoft device-login portal. The victim would complete their normal authentication but inadvertently authorize the attacker’s session.
Microsoft identified the operators behind EvilTokens as "Storm-2992." SpyCloud’s investigation revealed that 8,708 compromised accounts were linked to 6,585 corporate email domains across 79 countries. TRM Labs investigated the financial infrastructure and cryptocurrency flows behind the operators, tracing payments and identifying purchasers on the Coinbase platform.
Notably, the top 10 most active EvilTokens customers accounted for 60% of the total unique victims in SpyCloud’s recaptured data, indicating a concentrated effort by a small number of high-volume operators. Trevor Hilligoss, chief intelligence officer at SpyCloud, suggests these operators are likely to migrate to competing PhaaS services and may already be utilizing multiple phishing kits to diversify their techniques and evade detection.
Microsoft recommends that organizations only allow device code flow where absolutely necessary and block it whenever possible to mitigate the risk of exploitation. The disruption preserved a significant amount of evidence, including customer accounts, chat logs, and payment traces, which law enforcement can utilize in their ongoing investigation and potential prosecution.
