Microsoft and partners disrupted EvilTokens, a device-code phishing service linked to more than 12,000 compromised inboxes across over 10,000 organizations, and UK police arrested two suspected operators tied to Storm-2992. Microsoft says the service was built to turn stolen mailbox access into business email compromise at scale.
The kit used OAuth device-code phishing to win a victim’s login session, then an AI chatbot read the real inbox to identify trusted contacts, payment approvals, and other details worth exploiting. That let attackers tailor fraud after they were already inside, and it also supported persistence by keeping access to the mailbox itself.
For Microsoft 365 and similar inbox-driven workflows, the lasting exposure is not just the lure that got clicked. Once an attacker has mailbox context and session access, finance and approval chains become part of the attack surface, and filtering alone does not contain what follows.