NewsTradingSentimentEventsCommunityBriefing
Tech

EvilTokens Platform Disrupted After 12,000 Account Compromises

By Tech Desk · · 2 min read
A stylized server rack in a data center with abstract digital lines connecting it to a shield icon.

Microsoft and partners have dismantled the EvilTokens platform, which exploited device code flows to breach 12,000 inboxes across 10,000 organizations.

Key points

  • EvilTokens compromised over 12,000 Microsoft accounts across 10,000 organizations using device code phishing techniques.
  • The platform offered cybercriminals AI-powered tools to identify high-value targets and generate contextually relevant fraud messages.
  • Two suspected administrators were arrested in the UK following a coordinated takedown by Microsoft, law enforcement, and SpyCloud.

Microsoft’s Digital Crimes Unit has successfully disrupted the EvilTokens phishing-as-a-service operation, a platform responsible for compromising over 12,000 Microsoft accounts within more than 10,000 organizations. The takedown marks a significant victory against a sophisticated cybercriminal service that emerged in February and quickly became a leading source of device code phishing attacks.

The operation was coordinated with the Health-ISAC, law enforcement agencies, and SpyCloud, an identity threat protection firm. Following the investigation, two men aged 32 and 38, suspected of administering the site, were arrested in the United Kingdom. Their arrest highlights the growing intensity of efforts to dismantle infrastructure that facilitates large-scale business email compromise campaigns.

Exploiting Legitimate Authentication Flows

EvilTokens specialized in device code phishing, a technique that abuses Microsoft’s OAuth 2.0 device-authorization flow. This flow is designed for devices with limited input capabilities, such as smart TVs or printers, but attackers used it to bypass multi-factor authentication. By tricking victims into entering a code on a legitimate login page, the platform obtained valid authentication tokens without needing to steal passwords.

This method allowed the service to compromise accounts even when strong security controls were in place. The platform offered this capability to cybercriminals for a monthly fee of $500 or a one-time cost of $1,500. As reported by BleepingComputer, the ease of access and the effectiveness of the technique led to a rapid surge in similar attacks, with at least ten other phishing platforms adopting this method by April.

AI-Driven Targeting and Fraud

Once inside an account, EvilTokens used AI-powered tools to analyze mailbox content and map organizational relationships via Microsoft Graph. The system could identify high-value targets by searching for wire-transfer information, pending invoices, and executive correspondence. This data was then used to generate contextually relevant business email compromise messages, making the fraud difficult for employees to detect.

The phishing lures impersonated various services, including document-signing platforms, Microsoft services, and invoicing systems. Subject lines ranged from construction bids to password-expiration warnings, designed to appear routine and urgent. This level of customization significantly increased the success rate of the attacks, leading to widespread financial and operational risks for the affected organizations.

Global Impact and Enforcement

Data recovered by SpyCloud indicates that more than 8,708 accounts across 6,585 corporate domains in 79 countries were breached. The impacted sectors included wholesale distribution, construction, financial services, healthcare, and higher education. Microsoft tracks the threat actor as Storm-2992, noting that the platform fueled sophisticated fraud campaigns globally.

The Metropolitan Police Service executed warrants at addresses in Canary Wharf and Nine Elms, arresting the two suspected administrators. Both suspects were released on bail pending further investigation. Detective Inspector Serena D'Adamo stated that the police remain committed to holding individuals accountable for facilitating criminal activities, emphasizing that they will continue to pursue those who believe they can operate undetected.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories