Executive Summary
EvilTokens emerged in February 2026 as a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992, compromising over 12,000 inboxes across 10,000+ organizations worldwide. The platform exploited OAuth device code authentication flows through AI-powered phishing campaigns, enabling cybercriminals to bypass multifactor authentication and steal authentication tokens at scale. EvilTokens featured 44 customizable phishing templates, automated AI assistants for crafting targeted lures, and multi-stage delivery pipelines designed to evade traditional email security controls.
This incident highlights the industrialization of token-based attacks as organizations increasingly adopt MFA, forcing threat actors to evolve beyond credential theft toward authentication bypass techniques that exploit legitimate OAuth flows and cloud service integrations.
Why This Matters Now
The EvilTokens campaign represents a critical evolution in phishing attacks, demonstrating how threat actors are weaponizing AI and legitimate authentication protocols to bypass modern security controls at unprecedented scale and sophistication.
Attack Path Analysis
EvilTokens phishing-as-a-service platform initiated attacks through device code phishing emails targeting organizational users. Following successful authentication, threat actors escalated privileges by obtaining OAuth tokens and registering devices for persistent access. They conducted lateral movement through Microsoft Graph API reconnaissance to map organizational structures. Command and control was maintained via polling mechanisms and AI-powered automation platforms. Exfiltration occurred through compromised email accounts with malicious inbox rules concealing communications. Impact manifested as business email compromise affecting over 12,000 inboxes across 10,000 organizations worldwide.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers delivered phishing emails with 44 different themes using malicious URLs, PDF attachments, and HTML files, leveraging multi-stage delivery pipeline through compromised domains and serverless platforms like Vercel, Cloudflare Workers, and AWS Lambda to evade detection
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Phishing for Information: Spearphishing Link
Multi-Factor Authentication Request Generation
Steal Application Access Token
Domain Policy Modification: Domain Trust Modification
Email Collection: Remote Email Collection
Hide Artifacts: Email Hiding Rules
Valid Accounts: Cloud Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Multi-factor authentication for all access
Control ID: 8.4.2
CISA Zero Trust Maturity Model 2.0 – Device Authentication and Authorization
Control ID: ID.AM-2
DORA – ICT Risk Management Framework
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Secure log-on procedures
Control ID: A.9.4.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
EvilTokens phishing-as-a-service platform directly targeted financial services with AI-powered BEC campaigns, exploiting device code authentication to bypass MFA protections and access sensitive financial communications.
Higher Education/Acadamia
Higher education institutions faced significant exposure to EvilTokens campaigns targeting organizational email systems, with AI-driven reconnaissance capabilities mapping academic structures and compromising administrative communications.
Health Care / Life Sciences
Healthcare organizations experienced targeted device code phishing attacks compromising patient data systems, with encrypted traffic capabilities and HIPAA compliance violations through token-based email exfiltration schemes.
Construction
Construction sector targeted through business partnership agreements and bid proposal phishing lures, enabling threat actors to compromise project communications and financial authorization workflows.
Sources
- Unmasking EvilTokens: Getting to the root of device code phishinghttps://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/Verified
- CISA Cybersecurity Advisory - Phishing-as-a-Service Platformshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249aVerified
- Riding the Rails: Threat Actors Abuse Railway.com PaaS as Microsoft 365 Token Attack Infrastructurehttps://www.huntress.com/blog/riding-the-rails-threat-actors-abuse-railway-com-paasVerified
- Microsoft Digital Crimes Unit Takes Action Against EvilTokens Infrastructurehttps://blogs.microsoft.com/on-the-issues/2026/09/22/digital-crimes-unit-eviltokens-disruption/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this OAuth token compromise by constraining lateral movement and limiting exfiltration paths through segmented access controls and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Segmented network architecture would likely limit the initial foothold scope by restricting compromised endpoint connectivity to only essential services rather than broad network access.
Control: Zero Trust Segmentation
Mitigation: Identity-scoped access controls would likely constrain the scope of compromised OAuth tokens by limiting token-based access to specific network segments rather than organization-wide resources.
Control: East-West Traffic Security
Mitigation: Microsegmentation enforcement would likely constrain API-based reconnaissance by blocking unauthorized east-west traffic between workloads and limiting Graph API queries to approved communication paths only.
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls would likely detect and constrain persistent polling behavior by identifying anomalous communication patterns and blocking unauthorized command channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit data exfiltration scope by restricting outbound communications to approved destinations and blocking unauthorized email forwarding or external data transfers.
While some organizations may still experience compromised accounts, the overall blast radius would likely be significantly reduced with constrained lateral access and limited exfiltration capabilities reducing cross-organizational impact.
Impact at a Glance
Affected Business Functions
- Email Communications
- Business Email Correspondence
- Financial Transaction Processing
- Executive Communications
Estimated downtime: 7 days
Estimated loss: $2,500,000
Compromised more than 12,000 inboxes across 10,000+ organizations worldwide. Exposed email contents, organizational structure data through Microsoft Graph reconnaissance, financial correspondence including wire transfer details and pending invoices, executive communications, and business partnership agreements across multiple industries including financial services, healthcare, construction, and higher education.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement through Microsoft Graph API reconnaissance and limit privilege escalation from compromised OAuth tokens
- • Deploy Multicloud Visibility & Control capabilities to detect anomalous Microsoft Graph API requests and suspicious automation patterns indicative of EvilTokens polling mechanisms
- • Enable Egress Security & Policy Enforcement with FQDN filtering to block outbound communications to serverless platforms (Vercel, Cloudflare Workers, AWS Lambda) commonly abused for phishing infrastructure
- • Configure Threat Detection & Anomaly Response systems to identify device code authentication flows and baseline normal authentication patterns to detect OAuth token abuse
- • Establish Cloud Firewall (ACF) with URL filtering and AI-powered traffic discovery to prevent access to phishing domains and detect multi-stage redirect schemes used in EvilTokens delivery pipeline



