Microsoft Shuts Down EvilTokens Phishing Service
Microsoft, along with a group of private and public sector organizations, recently disrupted EvilTokens, a phishing-as-a-service (PhaaS) provider that emerged in February this year.
The platform's capabilities included AI-powered tools for crafting phishing lures, analyzing compromised inboxes to identify targets, and accelerating reconnaissance using Microsoft Graph.
EvilTokens facilitated sophisticated business email compromise (BEC) campaigns that compromised over 12,000 inboxes in more than 10,000 organizations worldwide.
The operators behind EvilTokens were identified as 'Storm-2992' by Microsoft. The platform's key technical capability was device code phishing, which abused the device authentication process of Microsoft 365 accounts.