← Back to Daily Briefing (#AIBot)

Microsoft Disrupts EvilTokens AI-Powered Phishing-as-a-Service Campaign

Published September 23, 2026

Microsoft, in coordination with law enforcement and industry partners, has dismantled EvilTokens, a Phishing-as-a-Service (PaaS) platform that exploited the Microsoft OAuth 2.0 device-code authentication flow. The campaign compromised over 12,000 Microsoft 365 mailboxes across 10,000 organizations globally by intercepting valid session tokens rather than traditional passwords. The platform utilized an integrated AI chatbot to automate mailbox reconnaissance and Business Email Compromise (BEC) fraud generation. The disruption involved seizing 50 websites and over 150 domains, following the arrest of two UK-based operators. This incident highlights the critical risk of abusing legitimate authentication flows to bypass multi-factor authentication (MFA) and the increasing integration of generative AI into automated cybercrime ecosystems.

  • Attack Vector and Exploitation Mechanics
  • Abuse of the OAuth 2.0 device-code flow to facilitate session hijacking without password theft.
  • Victims are directed to attacker-controlled sites to enter legitimate Microsoft device codes, granting the attacker valid access tokens.
  • Extracted tokens allow for direct mailbox access, effectively bypassing standard MFA protections through the use of valid, authenticated sessions.

  • AI-Enhanced Phishing-as-a-Service (PaaS) Model

  • Operates as a subscription-based platform featuring a centralized dashboard and Telegram-based marketing channels.
  • Integration of an AI-driven analyst bot designed to automate mailbox reconnaissance and draft sophisticated BEC fraud messages.
  • Revenue model required a $1,500 upfront fee plus a $500 monthly subscription for service access.

  • Campaign Scale and Global Impact

  • Impacted >12,000 Microsoft 365 inboxes across more than 10,000 organizations worldwide.
  • Targeted diverse sectors, including financial services, healthcare, higher education, and wholesale distribution.
  • Financial traces linked approximately $1.1 million in illicit proceeds to over 700 distinct cryptocurrency addresses.

  • Law Enforcement Takedown and Infrastructure Seizure

  • Coordinated global operation resulted in the seizure of 50 websites and over 150 associated domains.
  • Led to the arrest of two UK-based suspects, who were subsequently released on bail.
  • Geographic reach of the campaign spanned North America, the UK, France, India, and Australia.

  • Defensive Strategies and Remediation

  • Enforce Conditional Access policies to restrict or disable the OAuth 2.0 device-code flow for non-essential users.
  • Implement shorter token lifetimes to minimize the window of opportunity for attackers using hijacked sessions.
  • Deploy real-time monitoring to detect anomalous authentication patterns and unusual device-code request spikes.

Related posts

  1. gbhackers.com — Microsoft Warns of EvilTokens AI Phishing Service Hijacking Thousands of Accounts
  2. cyberscoop.com — Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
  3. thehackernews.com — Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
  4. news.microsoft.com — Disrupting EvilTokens: Taking down an AI-powered cybercrime platform
  5. csoonline.com — Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime
  6. Helpnetsecurity
  7. Cloudflare
  8. Securityweek

LINK COPIED TO CLIPBOARD