Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » EvilTokens PhaaS Takedown: Microsoft Seizes 50 Sites, Two Arrested in UK
    Technology

    EvilTokens PhaaS Takedown: Microsoft Seizes 50 Sites, Two Arrested in UK

    Gary BehanBy Gary Behan01/10/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    EvilTokens PhaaS takedown
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    Microsoft‘s Digital Crimes Unit has led the disruption of the EvilTokens PhaaS takedown operation, seizing infrastructure tied to a phishing-as-a-service platform that compromised more than 12,000 Microsoft accounts across over 10,000 organisations worldwide. Two men, aged 32 and 38, were arrested in the UK in connection with the alleged operation of the service.

    EvilTokens emerged in February and quickly distinguished itself. It was the first phishing-as-a-service platform to support device-code authentication at scale, and it layered in AI-powered tools for customising phishing lures and sifting through compromised inboxes to identify high-value targets. That combination made it unusually dangerous, and it attracted serious attention from law enforcement and industry alike.

    EvilTokens PhaaS Takedown: What Microsoft and Partners Actually Did

    Microsoft coordinated the action with the Health-ISAC, law enforcement, and SpyCloud, an identity threat protection company based in Austin, Texas. According to The Register, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. That is a meaningful dent, even if the threat itself has not been eliminated entirely: Microsoft’s own statement makes clear this was not a full takedown, and attacks are expected to decrease in volume rather than stop.

    On the arrests: the Metropolitan Police Service’s cybercrime team detained the two suspects on 11 September, executing warrants at addresses in Canary Wharf and Nine Elms. Both were released on bail pending further investigation. ‘The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected. We will find you and take action,’ Detective Inspector Serena D’Adamo told BleepingComputer.

    Quartz reports that Coinbase, which participated in the broader investigation, estimated EvilTokens generated roughly $1.1 million in revenue. The platform was sold on Telegram at $500 per month or a one-time fee of $1,500, with add-ons such as anti-bot redirectors, B2B and SMTP sending tools, and an Office 365 capture-link tool sold separately. Forty-four customisable phishing kits were included in the base service.

    How Device-Code Phishing Bypasses MFA at Scale

    EvilTokens specialised in device-code phishing, a technique that abuses Microsoft’s legitimate OAuth 2.0 device-authorisation flow. That flow was designed for devices with limited input capabilities (smart TVs, printers, conferencing equipment) but EvilTokens weaponised it to obtain authentication tokens even when multi-factor authentication was active, meaning attackers could compromise accounts without ever stealing a password.

    An attack begins when the attacker initiates a device-code request and forwards the resulting code to a target as part of a phishing lure. The victim is directed to a page showing the code alongside a button linking to Microsoft’s legitimate login portal, where they authenticate normally, handing over a valid token in the process. The technique has spread quickly: by April, at least 10 phishing platforms were offering the capability.

    Microsoft tracks the EvilTokens operator as Storm-2992. Campaigns using the platform hit organisations across wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud’s data shows more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries, with roughly 97.5% of those accounts belonging to enterprise domains. The most targeted country was the United States, followed by Canada, Australia, the United Kingdom, and Saudi Arabia.

    Once inside an account, EvilTokens used Microsoft Graph to map organisational relationships, then applied AI tools to search mailboxes for wire-transfer information, pending invoices, and executive correspondence. The platform could generate contextually relevant business email compromise messages from that material. To evade detection, it routed traffic through compromised sites and legitimate cloud platforms including Vercel, Cloudflare Workers, and AWS Lambda, and used multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages to slow automated analysis.

    EvilTokens is far from the only platform of its kind, and affiliates have already produced clones such as APToken. Organisations defending against device-code phishing should disable the device-code authentication flow wherever it is not required, monitor for suspicious login activity, and consider phishing-resistant methods such as FIDO2 security keys or passkeys.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleBigDiskBuster Windows Defender zero-day exploit freezes antivirus updates
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    BigDiskBuster Windows Defender zero-day exploit freezes antivirus updates

    01/10/2026

    Zyxel GS1900 Switch Exploit Hits 996 Devices as CISA Orders Federal Patch

    01/10/2026

    BigCommerce Ribon app breach exposes shoppers at Master of Malt and beyond

    30/09/2026

    Microsoft 365 Companion Apps Retirement Set for 16 December

    30/09/2026

    Ireland’s DPC hits Google with €403m location data fine

    30/09/2026

    September Windows Updates Trigger File History Backup Bug Across Windows 10 and 11

    29/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.