Overview
- Microsoft’s Digital Crimes Unit led a multi‑partner operation announced Tuesday that seized 50 websites and disabled more than 150 domains tied to EvilTokens and that helped UK police arrest two suspected operators who were later released on bail.
- The service had compromised over 12,000 Microsoft 365 inboxes at more than 10,000 organizations across 79 countries, with most victims in the United States and notable clusters in Canada, the UK, Australia, India and France.
- EvilTokens abused the OAuth device‑authorization flow by tricking users into entering attacker‑provided device codes on legitimate sign‑in pages, which granted attackers valid session tokens that bypassed multifactor authentication and could persist after password resets unless sessions and tokens were revoked.
- The platform combined AI throughout the attack chain — an inbox‑analysis chatbot, automated targeting of payment authorities, and template generation for BEC lures — and was sold via Telegram as a subscription service whose crypto receipts were traced by Coinbase to roughly $1.1 million.
- Industry partners warn the disruption will cut immediate volume but not eliminate the threat because the device‑code phishing plus AI PhaaS model is easily copied; defenders are urged to revoke tokens, restrict or disable device‑code flows, and adopt phishing‑resistant authentication like FIDO2 keys.