Executive Summary
In September 2026, Microsoft successfully disrupted EvilTokens, a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992. The AI-powered cybercrime service facilitated device code phishing attacks targeting Microsoft 365 accounts, compromising over 12,000 inboxes across 10,000+ organizations worldwide. Microsoft seized 50 websites and disabled 150+ domains, while UK authorities arrested two suspects. EvilTokens distinguished itself by automating device code authentication abuse at scale, using AI to craft tailored phishing lures, analyze compromised inboxes for high-value targets, and streamline business email compromise campaigns sold for $1,500 upfront plus $500 monthly via Telegram.
This incident highlights the alarming evolution of phishing-as-a-service platforms leveraging AI to democratize sophisticated attacks. As threat actors increasingly weaponize legitimate authentication mechanisms and AI capabilities, organizations face unprecedented challenges in defending against automated, scalable identity-based attacks that bypass traditional security controls.
Why This Matters Now
The EvilTokens disruption reveals how AI is accelerating the commoditization of advanced phishing techniques, making device code authentication abuse accessible to lower-skilled attackers. This trend demands immediate reassessment of identity security controls and authentication policies.
Attack Path Analysis
EvilTokens PhaaS platform conducted device code phishing attacks to compromise Microsoft 365 accounts, then used AI-powered analysis to identify high-value targets within organizations for follow-on BEC campaigns. Attackers leveraged legitimate Microsoft Graph API access to map organizational structures and escalate privileges, then conducted reconnaissance across compromised environments to identify payment authorities and sensitive data for financial fraud and business email compromise attacks.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims clicked phishing links that initiated Microsoft's legitimate device authentication process, redirecting to malicious pages displaying device codes before sending users to legitimate Microsoft login portals where they inadvertently authorized attacker sessions
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Valid Accounts: Cloud Accounts
Multi-Factor Authentication Request Generation
Steal Application Access Token
Account Discovery: Email Account
Email Collection: Remote Email Collection
Native API
Data Manipulation: Transmitted Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor authentication for administrative access
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-factor authentication
Control ID: 500.12
CISA ZTMM 2.0 – Identity and device inventory
Control ID: ID.AM-2
DORA – ICT risk management framework
Control ID: Article 11
NIS2 Directive – Cybersecurity risk management measures
Control ID: Article 21
GDPR – Security of processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value targets for BEC campaigns with payment authority; device code phishing compromises sensitive financial communications and regulatory compliance requirements.
Information Technology/IT
Microsoft 365 infrastructure dependency creates significant exposure to device code phishing attacks targeting IT service providers and cloud environments.
Higher Education/Acadamia
Educational institutions using Microsoft 365 face credential theft risks affecting student data, research communications, and administrative payment processes.
Health Care / Life Sciences
HIPAA compliance violations from compromised Microsoft 365 accounts; patient data exposure through AI-powered inbox analysis and organizational reconnaissance.
Sources
- Microsoft Disrupts EvilTokens Device Code Phishing Servicehttps://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-serviceVerified
- Microsoft Security Blog: Disrupting EvilTokens Phishing-as-a-Service Operationhttps://www.microsoft.com/security/blog/2026/09/22/disrupting-eviltokens-phishing-as-a-service-operation/Verified
- SpyCloud Research: EvilTokens Investigation Findingshttps://spycloud.com/resource/eviltokens-investigation/Verified
- Metropolitan Police Service Cybercrime Unit Arrests Related to EvilTokenshttps://news.met.police.uk/news/two-arrested-connection-eviltokens-cybercrime-operationVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this Microsoft 365 compromise by limiting organizational access scope and reducing lateral reconnaissance capabilities. East-west segmentation and egress controls could significantly reduce the blast radius of AI-powered data harvesting across compromised environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware access controls would likely limit the scope of Microsoft 365 token permissions and reduce the organizational reach available through compromised device authentication flows
Control: Zero Trust Segmentation
Mitigation: Workload isolation and identity-scoped access policies would likely restrict Microsoft Graph API queries to specific organizational segments rather than allowing broad directory enumeration
Control: East-West Traffic Security
Mitigation: East-west segmentation would likely constrain cross-departmental email access and reduce the ability to correlate organizational relationships across isolated business units during reconnaissance activities
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and monitoring would likely detect anomalous Microsoft 365 session patterns and provide behavioral analysis of compromised token usage across cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit bulk data extraction and constrain the volume of organizational intelligence that could be systematically harvested from compromised email environments
While BEC campaigns could still occur, the reduced organizational intelligence and constrained reconnaissance scope would likely limit targeting precision and reduce the effectiveness of AI-crafted social engineering
Impact at a Glance
Affected Business Functions
- Email Communications
- Identity and Access Management
- Financial Operations
- Business Email Correspondence
Estimated downtime: 7 days
Estimated loss: N/A
Compromised Microsoft 365 accounts across 12,000 inboxes in over 10,000 organizations spanning 79 countries. Exposed business email communications, organizational structures, payment authorities, and sensitive corporate relationships used for follow-on BEC attacks.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between compromised accounts and sensitive organizational resources
- • Deploy Egress Security & Policy Enforcement to block unauthorized Microsoft Graph API calls and data exfiltration to external domains
- • Enable Multicloud Visibility & Control to detect anomalous authentication patterns and repeated API requests indicative of automated reconnaissance
- • Configure Cloud Native Security Fabric (CNSF) with real-time inspection to identify and block device code phishing attempts at the network layer
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal Microsoft 365 usage patterns and alert on suspicious inbox analysis activities



