"The Met remains committed to holding people to account who facilitate criminal enabling functions and think they can remain undetected. We will find you and take action," Detective Inspector Serena D'Adamo told BleepingComputer.
Microsoft’s Digital Crimes Unit led a coordinated disruption and U.K. arrests
Microsoft said it coordinated a disruption of the EvilTokens phishing-as-a-service platform, with assistance from the Health-ISAC, law enforcement, and SpyCloud. The company said it obtained legal authority to seize active infrastructure associated with the service. As part of the follow-up, two men, aged 32 and 38, suspected of being administrators of the EvilTokens website were arrested in the U.K. The Metropolitan Police Service received information about the suspects in August and executed warrants at addresses in Canary Wharf and Nine Elms; both suspects were released on bail pending further investigation.
How EvilTokens weaponized the OAuth 2.0 device-authorization flow
Researchers described EvilTokens as specializing in device-code phishing, a technique that abuses Microsoft’s legitimate OAuth 2.0 device-authorization flow — a workflow designed for devices with limited input capabilities such as smart TVs, printers, conferencing equipment, and some Teams devices. The attack flow begins with an attacker initiating a device-code request and sending the received code to a target inside a phishing lure. The victim is directed to a page showing the code and a button that links to Microsoft’s legitimate login portal, where the user is prompted to authenticate. That authentication yields tokens that allow account compromise without traditional credential theft, even when multifactor protections are present.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScale and impact: over 12,000 inboxes, tens of thousands of affected organizations and accounts
Microsoft reported that EvilTokens compromised more than 12,000 inboxes across over 10,000 organizations worldwide, fueling what the company called "sophisticated business email compromise (BEC) campaigns." SpyCloud’s recaptured phished data shows more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries. SpyCloud’s dataset indicates the service focused on businesses: roughly 97.5% of compromised accounts belonged to enterprise domains. The most targeted countries were the United States, followed by Canada, Australia, the United Kingdom, and Saudi Arabia.
EvilTokens’ commercial model, tooling, and evasion techniques
Storm-2992 is the name Microsoft uses to track the actor behind EvilTokens. The platform emerged in February and was the first, researchers said, to scale support for device-code authentication and to offer AI-powered features that customize lures and sift through compromised inboxes for high-value targets. Storm-2992 promoted EvilTokens on Telegram, offering access for $500 per month or a one-time fee of $1,500. Add-ons were sold separately, including anti-bot redirectors, B2B and SMTP sending tools, and an Office 365 capture-link tool. The service provided 44 customizable phishing kits.
- Lures impersonated document-signing platforms, Microsoft services, cloud identity and file-sharing providers, invoicing systems, voicemail, and eFax services.
- Subjects of phishing emails included construction bids, partnership agreements, compensation and benefits notices, requests for proposals, shared files, invoices, and password-expiration warnings.
- After initial access, the platform used Microsoft Graph to map organizational relationships and AI-powered tools to analyze mailbox content for wire-transfer information, pending invoices, and executive correspondence — then generate contextually relevant BEC messages.
- To evade detection and impede automated analysis, EvilTokens used multi-stage redirects, PDFs, HTML attachments, fake CAPTCHA pages, and routing through compromised sites and legitimate cloud platforms such as Vercel, Cloudflare Workers, and AWS Lambda.
What this means for technologists, enterprises, and end users
Technologists and security teams should consider disabling device-code authentication where it is not required and block the device-code flow where possible; monitor for suspicious login activity; and prioritize phishing-resistant authentication methods such as FIDO2 security keys or passkeys, actions recommended in the Microsoft advisory.
Enterprises and procurement leaders will need to reassess reliance on device-authorization flows in environments that do not require them, and to scrutinize external email flows for highly contextual BEC content that can be auto-generated and tailored by the platform.
End users should verify the application they are authenticating to and avoid proceeding if they are not signing in to an expected app, since device-code phishing relies on convincing users to approve authentication requests that appear legitimate.
Microsoft and partners framed the action as a disruption rather than a definitive takedown: the company warned that the threat remains active and that affiliates have already produced “clones” such as APToken. While the seizure of infrastructure should noticeably reduce attack volume, the combination of a paid service model, AI-enabled mailbox analysis, and exploits of legitimate authentication workflows means defenders must treat device-code phishing as a persistent, evolving vector.
Source: BleepingComputer — EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts




