Microsoft and UK law enforcement have disrupted the EvilTokens phishing-as-a-service platform, seizing its infrastructure and arresting two alleged administrators after the kit was used to compromise thousands of Microsoft 365 accounts worldwide[1][3][5].
EvilTokens is a turnkey phishing kit that abuses Microsoft’s OAuth 2.0 device authorization grant to capture access and refresh tokens, allowing criminals to bypass multi-factor authentication and silently authenticate as victims in Microsoft 365 and Entra ID environments[5][6][10]. Unlike traditional credential-stealing phishing, device-code attacks trick users into entering a short code at a legitimate Microsoft verification portal, resulting in valid tokens being issued directly to attacker-controlled infrastructure without ever stealing passwords[5][7][15].
Researchers first observed EvilTokens campaigns in mid-February 2026, with Sekoia’s Threat Detection and Research team and the Cloud Security Alliance documenting its rapid adoption among business email compromise crews[6][10][13]. By early April, the service was being sold via Telegram and had already been used to compromise more than 12,000 mailboxes across over 10,000 organizations, with 10 to 15 distinct phishing campaigns launching every 24 hours, according to Microsoft vice president of security research Tanmay Ganacharya[1][3][11]. The kit’s appeal stems from its automation: it provides a webmail-style interface, token “weaponisation” features, and AI-powered tooling that can exfiltrate emails, perform reconnaissance through Microsoft Graph, and streamline BEC fraud workflows[4][13][15].
Late last week, Microsoft’s Digital Crimes Unit (DCU) obtained court orders from the US District Court for the Eastern District of Virginia and, working with Health-ISAC, moved to take down the EvilTokens infrastructure, including seizing around 50 websites that operated the service and disabling more than 150 additional domains supporting its campaigns[1][5]. Partners including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs assisted in dismantling the platform and related infrastructure, while Microsoft notified affected customers to help them remediate compromised accounts[1][6]. In parallel, London’s Metropolitan Police Service arrested two men, aged 32 and 38, on September 18 on suspicion of administering EvilTokens, later releasing them on bail as the investigation continues, with Detective Inspector Serena D’Adamo stressing that phishing services “bring misery to thousands” and that facilitators of such crime “think they can remain undetected” at their peril[1].
Healthcare organizations were among those hit by EvilTokens-powered campaigns, prompting Health-ISAC to join Microsoft’s legal action as a co-plaintiff in order to protect hospitals and other medical entities increasingly targeted for high-value BEC and ransomware operations[1][12]. Microsoft said the operation marks DCU’s 40th court-authorized disruption over nearly two decades and its first case against what it describes as an end-to-end AI-enabled cybercrime service, underscoring how generative and analytic AI are now embedded across the phishing kill chain—from lure generation to post-compromise account takeover[1][4]. Associate general counsel and DCU general manager Steven Masada warned that while EvilTokens’ infrastructure has been disrupted, the model it pioneered will persist, and organizations should assume that once an inbox is breached, criminals can understand its contents in minutes rather than days[1][13].
Security teams should respond by hardening identity protections, closely monitoring sign-ins involving device-code or other noninteractive flows, and limiting where and how OAuth device authorization can be used in enterprise environments[6][10][15]. Independent verification of any request to change payment information, redirect funds or approve unusual transactions via a trusted second channel remains critical, particularly for finance and healthcare teams that are prime BEC targets[1][12][13]. While the takedown of EvilTokens shows that coordinated legal and technical action can disrupt phishing-as-a-service ecosystems, defenders should expect copycat platforms to emerge and treat AI-augmented phishing as a sustained, structural shift in the threat landscape rather than a one-off campaign[4][5][15].
References
- EvilTokens device-code phishing kit totally more evil than we all …
- Hundreds compromised daily in Microsoft device code phishes
- EvilTokens: an AI-augmented phishing kit for automating BEC …
- EvilTokens Malware Analysis, Overview by ANY.RUN
- EvilTokens: Device-Code Phishing Renders MFA Irrelevant
- EvilTokens: A phishing attack that doesn’t steal your password
- New widespread EvilTokens kit: device code phishing as-a-service
- New EvilTokens service fuels Microsoft device code …
- EvilTokens device code phishing attacks surge 1380%
- Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five …
- EvilTokens: Turning OAuth Device Codes into Full-Scale BEC Operations
