Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact

← Back to insights

Threat Actors

Microsoft Disrupts EvilTokens Device‑Code Phishing‑as‑a‑Service Platform

23 September 2026 LetsDefend Infosec 5 min read

Introduction

Microsoft announced a coordinated takedown of the EvilTokens device‑code phishing‑as‑a‑service (PaaS) platform that was targeting Microsoft 365 accounts. The operation, executed under a U.S. District Court order and with assistance from a broad set of industry partners, resulted in the seizure of 50 websites and the disabling of more than 150 domains. The disruption aims to cut off a supply chain that had already compromised a significant number of user inboxes.

What Happened

The EvilTokens service offered attackers a turnkey solution for harvesting Microsoft 365 credentials. By leveraging device‑code authentication flows, the platform could obtain tokens without requiring victims to enter passwords directly. Microsoft disclosed that the service was actively exploiting these flows and had been linked to approximately 12,000 compromised inboxes. The takedown was authorized by the U.S. District Court for the Eastern District of Virginia and involved a coalition that included Health‑ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver.

Technical Details

The phishing‑as‑a‑service model operated on a multi‑stage pipeline:

  1. Infrastructure Hosting – Malicious actors maintained over 150 domains that served phishing pages and command‑and‑control (C2) functions. Microsoft’s seizure removed 50 of these sites outright.
  2. AI‑Enhanced Lures – According to Microsoft, artificial intelligence was employed at each stage, from generating convincing email content to automating the selection of victim accounts. While the claim originates from Microsoft’s statement, independent verification has not been published.
  3. Device‑Code Flow Abuse – Attackers initiated the OAuth device‑code flow, presenting victims with a code to enter on a malicious site. Once entered, the service obtained an access token for the victim’s Microsoft 365 account without prompting for a password.
  4. Credential Harvesting and Resale – Stolen tokens were either used directly for lateral movement within compromised tenants or sold on underground markets. The involvement of partners such as Coinbase suggests that some proceeds may have been laundered through cryptocurrency channels.

The coordinated effort disabled more than 150 domains, effectively severing the C2 pathways and preventing further token issuance. By seizing 50 websites, Microsoft removed the primary delivery vectors used to lure victims.

Who Is Affected

The primary victim set consists of Microsoft 365 users whose inboxes were compromised. While Microsoft has not released a precise list of affected organizations, the scale of the operation—tied to 12,000 inbox compromises—indicates that both enterprise and consumer accounts were likely targeted. Organizations that rely heavily on Microsoft 365 for email, collaboration, and identity management should assume exposure until they verify the integrity of their accounts.

Why It Matters

Disrupting a phishing‑as‑a‑service platform removes a critical enabler for a wide range of threat actors. The EvilTokens service lowered the technical barrier for less‑sophisticated groups to launch credential‑theft campaigns against high‑value cloud services. By eliminating the infrastructure, Microsoft not only halted ongoing compromises but also sent a clear signal that coordinated legal and industry action can dismantle profitable cybercrime ecosystems.

The alleged use of AI throughout the attack chain raises concerns about the future efficiency of phishing campaigns. If artificial‑intelligence tools can automate social‑engineering at scale, defenders must adapt detection and response processes accordingly.

Exploitation/Attack Information

EvilTokens was actively exploited at the time of the takedown. The service leveraged the OAuth device‑code flow, a legitimate authentication mechanism, to bypass traditional password‑based defenses. Attackers distributed phishing emails that mimicked legitimate Microsoft communications, prompting users to enter a short code on a malicious site. Successful entry yielded an access token granting the attacker full mailbox access and, in many cases, the ability to read or send email on behalf of the victim.

The operation’s scale suggests a high degree of automation. The involvement of AI, as claimed by Microsoft, would enable rapid generation of personalized phishing content, increasing the likelihood of user interaction. While the exact AI models and datasets remain undisclosed, the reported capability underscores a shift toward more sophisticated, data‑driven social engineering.

Recommended Actions

Organizations should treat the EvilTokens takedown as a prompt to review their Microsoft 365 security posture. The following steps are advised:

  • Audit OAuth Applications – Review all third‑party applications that have been granted device‑code or other OAuth permissions. Revoke any that are unnecessary or unverified.
  • Enforce Conditional Access – Deploy policies that require multi‑factor authentication (MFA) for token issuance, especially for high‑privilege accounts.
  • Monitor Sign‑In Anomalies – Enable Azure AD sign‑in risk detection and set alerts for unusual locations, devices, or token requests.
  • Educate End Users – Conduct targeted phishing awareness training that includes examples of device‑code flow attacks and the importance of verifying URLs before entering codes.
  • Leverage Threat Intelligence Feeds – Incorporate indicators of compromise (IOCs) related to the seized domains and IP addresses into security information and event management (SIEM) solutions.
  • Validate Mailbox Integrity – Perform mailbox audits to detect unauthorized forwarding rules, mailbox export activities, or anomalous email patterns.

By implementing these controls, organizations can reduce the attack surface that EvilTokens and similar services exploit.

Conclusion

Microsoft’s court‑backed operation dismantled a significant phishing‑as‑a‑service infrastructure that had compromised thousands of Microsoft 365 accounts. The seizure of 50 websites and the disabling of over 150 domains crippled the EvilTokens platform’s ability to issue fraudulent device‑code tokens. While the exact number of compromised inboxes remains unverified, the incident highlights the growing sophistication of AI‑enhanced phishing campaigns and the necessity for robust OAuth governance, MFA enforcement, and continuous user education. The collaborative effort between a federal court, Microsoft, and a diverse set of industry partners demonstrates a viable model for future takedowns of illicit cyber‑infrastructure.

Sources

  • The Hacker News: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
  • Dark Reading: https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
#Threat Intelligence #Phishing #Microsoft 365 #Domain Seizure #AI Threats
Share:
On this page
Introduction What Happened Technical Details Who Is Affected Why It Matters Exploitation/Attack Information Recommended Actions Conclusion Sources

Have a question about your own security posture?

Related insights
Vulnerabilities
28 Sep 2026 5 min read

Citrix NetScaler ADC & Gateway Critical RCE Vulnerabilities Actively Exploited

Citrix disclosed two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway that are being exploited in the wild. Patches have been released, but one vulnerability affects every deployment, including default configurations.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

CISA Flags Actively Exploited SharePoint Flaw (CVE‑2026‑65660) with Federal Patch Deadline

CISA has added CVE‑2026‑65660 for Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a September 28 patch deadline for federal agencies. Immediate remediation is required.

LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

Citrix NetScaler Zero‑Day Exploits (CVE‑2026‑88771/88772) Actively Attacked

Citrix disclosed two critical NetScaler remote code execution flaws, CVE‑2026‑88771 and CVE‑2026‑88772, that are currently being exploited. Security updates are available, and administrators are urged to shut down vulnerable appliances immediately.

LetsDefend Infosec Read more

Have a question about your own security posture?

LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.