Understanding EvilTokens: How device code phishing surpasses MFA?

EvilTokens is a phishing-as-a-service (PhaaS) platform that turned a legitimate Microsoft sign-in flow into an industrial-scale account takeover tool. Microsoft says the infrastructure helped compromise more than 12,000 inboxes at over 10,000 organizations worldwide before a coordinated disruption in September 2026.

Victims do not necessarily enter a password on a fake page. Instead, they may sign in on Microsoft’s legitimate domain and inadvertently authorize a session initiated by the attacker. A padlock icon or legitimate sign-in domain alone is therefore not enough to identify this form of phishing.

Mã đăng nhập thiết bị do EvilTokens tạo
EvilTokens generates a device sign-in code and directs the victim to Microsoft’s legitimate portal. Image: Microsoft Threat Intelligence

What Is a Device Code?

The device code flow is an OAuth mechanism for devices with limited input capabilities, such as smart TVs, printers, conferencing systems, and some Microsoft Teams devices. The device displays a short code; the user opens a browser elsewhere, visits the official sign-in page, enters the code, and completes authentication.

The mechanism is useful, but the requesting session and the device used for authentication are not as tightly bound as in a normal interactive sign-in. An attacker can initiate the request on their device and trick the victim into entering the code. When the victim authenticates, the token is issued to the attacker’s session.

Why Can MFA Still Be Bypassed?

MFA is not cryptographically broken. The victim completes the multifactor step correctly but approves a request created by the adversary. The attacker receives an access token without knowing the password and can use the account’s privileges while the token remains valid.

This is the key difference between traditional credential theft and consent-based deception. Changing the password may not be sufficient if tokens, sessions, mailbox rules, or registered devices have not been revoked and reviewed.

How Did EvilTokens Industrialize the Attack?

According to Microsoft, EvilTokens emerged in February 2026 and was operated by the actor tracked as Storm-2992. The service offered a control panel, redirect infrastructure, attachments, landing pages, and 44 customizable phishing themes. It was advertised for an initial USD 1,500 or USD 500 per month, excluding certain add-ons.

Lures impersonated requests for proposals, invoices, shared documents, password-expiration notices, voicemail, and document-signing platforms. The multilayer infrastructure used PDFs, HTML files, fake CAPTCHAs, compromised websites, and legitimate cloud services to evade automated filters.

How AI Was Used After Mailbox Compromise

After obtaining a token, EvilTokens could use Microsoft Graph to map organizational relationships, discover permissions, and analyze mailbox content. AI assistants helped identify invoices, wire transfers, and executive conversations, then generate business email compromise messages grounded in real context.

This made the next attack stage more convincing. A fraudulent message based on a real thread, sent from a compromised account, and directed to the person responsible for payments is much harder to detect than bulk phishing.

Impact and Disruption

Microsoft observed more than 12,000 compromised inboxes across over 10,000 organizations in distribution, construction, financial services, real estate, higher education, and healthcare. Data recovered by SpyCloud indicates that most affected accounts belonged to enterprise domains.

Microsoft’s Digital Crimes Unit worked with partners and law enforcement to disrupt EvilTokens infrastructure. Two suspected service administrators were arrested in the United Kingdom and released on bail as the investigation continues. This is not the end of the threat: similar kits and clones can remain active.

Warning Signs to Monitor

  • A user receives a device sign-in code without setting up a TV, printer, or conferencing device.
  • Entra ID logs show a device code sign-in from an unexpected location, IP address, or application.
  • Mailbox rules automatically delete, forward, or hide payment and security messages.
  • Unusual Microsoft Graph queries, new device registrations, or mailbox access follow a suspicious authentication event.
  • Internal email suddenly requests a change of payment account, gift-card purchases, or urgent invoice handling.

How Organizations Can Reduce Risk

Microsoft recommends blocking the device code flow when it is not required. If some Teams devices truly depend on it, exceptions should be limited to the necessary resource accounts and devices instead of enabling the flow broadly for all users.

Organizations should prioritize phishing-resistant authentication such as FIDO2 keys or passkeys, apply Conditional Access, monitor risky sign-ins, and alert on device code flows outside expected contexts. Third-party email connectors, mail-flow rules, and spoofing protections should also be configured correctly to reduce lure delivery.

When compromise is suspected, responders should revoke sessions and refresh tokens; review registered devices, consented applications, mailbox rules, forwarding, and Microsoft Graph activity; and examine transactions or internal messages originating from the account.

Lessons for Users

An official sign-in page can still be part of a phishing chain. Before entering a device code, users should ask whether they initiated a device connection, where the code came from, and which application is requesting access. Without clear context, stop and contact IT through an independent channel.

For organizations, the key principle is to reduce unnecessary authentication surfaces and detect post-sign-in behavior rather than focusing only on passwords. EvilTokens shows how industrialized token issuance combined with AI can turn an ordinary approval into the starting point for large-scale financial fraud.

VNCyberS compiled from Microsoft and BleepingComputer

Contact Us

Email: [email protected]
Phone: +84 903260277