Microsoft and partners disrupted EvilTokens, a device-code phishing service linked to more than 12,000 compromised inboxes across over 10,000 organizations, and UK police arrested two suspected operators tied to Storm-2992. Microsoft says the service was built to turn stolen mailbox access into business email compromise at scale.
The kit used OAuth device-code phishing to win a victim’s login session, then an AI chatbot read the real inbox to identify trusted contacts, payment approvals, and other details worth exploiting. That let attackers tailor fraud after they were already inside, and it also supported persistence by keeping access to the mailbox itself.
For Microsoft 365 and similar inbox-driven workflows, the lasting exposure is not just the lure that got clicked. Once an attacker has mailbox context and session access, finance and approval chains become part of the attack surface, and filtering alone does not contain what follows.
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
The popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise.
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).