Microsoft‘s Digital Crimes Unit has led the disruption of the EvilTokens PhaaS takedown operation, seizing infrastructure tied to a phishing-as-a-service platform that compromised more than 12,000 Microsoft accounts across over 10,000 organisations worldwide. Two men, aged 32 and 38, were arrested in the UK in connection with the alleged operation of the service.
EvilTokens emerged in February and quickly distinguished itself. It was the first phishing-as-a-service platform to support device-code authentication at scale, and it layered in AI-powered tools for customising phishing lures and sifting through compromised inboxes to identify high-value targets. That combination made it unusually dangerous, and it attracted serious attention from law enforcement and industry alike.
EvilTokens PhaaS Takedown: What Microsoft and Partners Actually Did
Microsoft coordinated the action with the Health-ISAC, law enforcement, and SpyCloud, an identity threat protection company based in Austin, Texas. According to The Register, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. That is a meaningful dent, even if the threat itself has not been eliminated entirely: Microsoft’s own statement makes clear this was not a full takedown, and attacks are expected to decrease in volume rather than stop.
On the arrests: the Metropolitan Police Service’s cybercrime team detained the two suspects on 11 September, executing warrants at addresses in Canary Wharf and Nine Elms. Both were released on bail pending further investigation. ‘The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected. We will find you and take action,’ Detective Inspector Serena D’Adamo told BleepingComputer.
Quartz reports that Coinbase, which participated in the broader investigation, estimated EvilTokens generated roughly $1.1 million in revenue. The platform was sold on Telegram at $500 per month or a one-time fee of $1,500, with add-ons such as anti-bot redirectors, B2B and SMTP sending tools, and an Office 365 capture-link tool sold separately. Forty-four customisable phishing kits were included in the base service.
How Device-Code Phishing Bypasses MFA at Scale
EvilTokens specialised in device-code phishing, a technique that abuses Microsoft’s legitimate OAuth 2.0 device-authorisation flow. That flow was designed for devices with limited input capabilities (smart TVs, printers, conferencing equipment) but EvilTokens weaponised it to obtain authentication tokens even when multi-factor authentication was active, meaning attackers could compromise accounts without ever stealing a password.
An attack begins when the attacker initiates a device-code request and forwards the resulting code to a target as part of a phishing lure. The victim is directed to a page showing the code alongside a button linking to Microsoft’s legitimate login portal, where they authenticate normally, handing over a valid token in the process. The technique has spread quickly: by April, at least 10 phishing platforms were offering the capability.
Microsoft tracks the EvilTokens operator as Storm-2992. Campaigns using the platform hit organisations across wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud’s data shows more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries, with roughly 97.5% of those accounts belonging to enterprise domains. The most targeted country was the United States, followed by Canada, Australia, the United Kingdom, and Saudi Arabia.
Once inside an account, EvilTokens used Microsoft Graph to map organisational relationships, then applied AI tools to search mailboxes for wire-transfer information, pending invoices, and executive correspondence. The platform could generate contextually relevant business email compromise messages from that material. To evade detection, it routed traffic through compromised sites and legitimate cloud platforms including Vercel, Cloudflare Workers, and AWS Lambda, and used multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages to slow automated analysis.
EvilTokens is far from the only platform of its kind, and affiliates have already produced clones such as APToken. Organisations defending against device-code phishing should disable the device-code authentication flow wherever it is not required, monitor for suspicious login activity, and consider phishing-resistant methods such as FIDO2 security keys or passkeys.

