Overview
- Microsoft led an industry operation that, on Tuesday, seized about 50 websites and disabled more than 150 domains tied to EvilTokens and began notifying and helping remediate affected customers.
- Two men in the U.K. were arrested in September in connection with the platform and released on police bail while investigations continue and partners shared evidence with law enforcement.
- EvilTokens used an AI-style chatbot to read compromised inboxes, find trusted contacts and payment approvals, and craft tailored phishing lures that let attackers harvest persistent OAuth session tokens without stealing passwords.
- Microsoft and partners tied the platform to roughly 12,000 compromised Microsoft inboxes across over 10,000 organizations, SpyCloud recovered about 8,700 affected accounts, and Coinbase traced about $1.1 million in cryptocurrency payments to the service.
- Defenders are advised to block or restrict OAuth device-code flows, adopt phishing-resistant sign-in methods such as FIDO2 or passkeys, revoke suspicious sessions and verify payment-change requests out of band because copycat services and device-code scams are likely to reappear.