Microsoft, Health-ISAC, law enforcement, and private-sector partners disrupted EvilTokens, an AI-enabled phishing-as-a-service platform attributed to threat actor Storm-2992. A federal court order enabled the seizure of 50 EvilTokens websites and the disabling of more than 175 supporting domains; UK Metropolitan Police also arrested two suspected operators in the greater London area. The service was linked to more than 12,000 compromised Microsoft customer inboxes across over 10,000 organizations worldwide, while known FBI IC3 complaints associated it with approximately $1.7 million in losses.
EvilTokens conducted OAuth 2.0 device-code phishing against Microsoft Entra ID, directing victims to Microsoft’s legitimate device-login page and capturing access and refresh tokens after authentication, thereby bypassing the practical protections of MFA. The platform used Microsoft Graph API access and an AI-style chatbot to examine stolen mailboxes for trusted contacts, payment information, high-value users, and global administrators, supporting business-email-compromise and financial-fraud operations. SpyCloud contributed recaptured data involving more than 8,700 victims, reporting that 97.5% of affected accounts were on enterprise domains; Coinbase traced roughly $1.1 million in revenue paid by the platform’s customers to its operators.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
The Metropolitan Police executed warrants in the greater London area and arrested two men, aged 32 and 38, on suspicion of making articles for use in fraud and money laundering. Police seized their digital devices and released both suspects on bail pending further investigation.
Microsoft and partners disrupted EvilTokens under a federal court order, seizing 50 websites used by the service and disabling more than 175 supporting domains.
Microsoft provided the UK Metropolitan Police with information concerning EvilTokens administrators, supporting the subsequent law-enforcement investigation.
Microsoft tracked an EvilTokens-aligned campaign that used automation platforms to deploy thousands of unique, short-lived polling nodes running Node.js backend logic. The infrastructure supported device-code phishing authorization monitoring while making detection and takedown more difficult.
Microsoft observed 10 to 15 distinct EvilTokens phishing campaigns launching every 24 hours beginning March 15, 2026, indicating sustained operational use of the platform.
SpyCloud recorded its first EvilTokens-related device-code token captures, marking observed victim activity associated with the platform.
EvilTokens, an AI-enabled phishing-as-a-service platform targeting Microsoft accounts, launched in February 2026.
Microsoft disclosed that EvilTokens, tracked as Storm-2992, compromised more than 12,000 Microsoft inboxes at over 10,000 organizations worldwide, facilitating business email compromise. SpyCloud data associated with the operation included more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
trmlabs.com
Open sourcemalware.news
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourcemicrosoft.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourcespycloud.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.