Microsoft Shuts Down EvilTokens Phishing Service Using AI
Microsoft announced the takedown of the EvilTokens device code phishing service that used AI to compromise email accounts and design roadmaps for financial fraud. The action was carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involving several organizations including Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs.
The service used AI to analyze a victim's inbox, identify trusted relationships, payment authorizations, and sensitive responsibilities. It even recommended fraud strategies, including drafting messages that impersonated trusted contacts to trick victims into taking action.
EvilTokens was first documented in March 2026 as a phishing-as-a-service (PhaaS) platform that abused the OAuth 2.0 device authorization flow. The threat actors behind EvilTokens were found to offer three different products, including EvilTokens B2B sender for $600 and EvilTokens Office 365 capture link for $1,500.
Microsoft tracked the threat actors as Storm-2992 and worked with other partners to seize 50 websites used to operate the service. Over 12,000 email inboxes across more than 10,000 organizations worldwide were linked to compromised accounts using EvilTokens.