Microsoft Shuts Down Major Phishing Operation Compromising Thousands of Accounts
A major phishing-as-a-service (PhaaS) operation known as EvilTokens has been disrupted after compromising over 12,000 Microsoft accounts across more than 10,000 organizations worldwide. The platform, which emerged in February and offered AI-powered features for customizing lures and sifting through compromised inboxes to identify high-value targets, was taken down in an effort led by Microsoft's Digital Crimes Unit (DCU). Two men suspected of being administrators of the EvilTokens website were arrested in the U.K. after warrants were executed at their addresses.
The researchers say that the cybercriminal service specializes in device-code phishing, a technique that abuses the device-code authentication flow to obtain authentication tokens despite MFA protections, allowing attackers to compromise accounts without needing credential theft. This led to a surge in device code phishing this year as multiple threat actors have adopted the method.
Microsoft and its partners disrupted EvilTokens by obtaining legal authority to seize active infrastructure associated with the phishing service; however, this was not a takedown operation, and the threat remains active, though attacks should noticeably decrease in volume. To defend against these attacks, organizations are advised to disable device-code authentication when it is not required and block the device-code flow wherever possible.