EvilTokens Device-Code Phish Hit 12,000 Inboxes

Security Affairs WordPress · High sophistication
Last updated September 24, 2026

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations and then impersonated finance staff or vendors in existing threads to redirect payments, including cryptocurrency. Microsoft, Coinbase, and partners disrupted the infrastructure and an alleged operator was arrested in London.

How the attack worked

EvilTokens was a phishing-as-a-service kit, attributed by Microsoft to a group called Storm-2992 and sold on Telegram. Victims received AI-generated emails styled as invoices, shared documents, or voicemail notifications, each containing a malicious link. Clicking the link led to a fake Microsoft or DocuSign page that displayed a code and instructed the victim to enter it on Microsoft's real login site to verify their identity. That single step authorized the attacker's session rather than a legitimate device request.

Why it succeeded

This is device code phishing: instead of a real device requesting access, the attacker initiates the login flow and hands the victim a code through a phishing lure. Because the victim completes the final step on Microsoft's own, legitimate infrastructure, MFA was bypassed entirely and no password was ever exposed. The attacker's access tokens also survived password resets, making the compromise harder to remediate once discovered.

What attackers did after gaining access

Once inside a mailbox, attackers:

  • Registered devices in Entra ID for persistent access
  • Created hidden inbox rules to suppress alerts and delete evidence
  • Used AI to search for payment-related conversations
  • Impersonated finance staff, vendors, or executives inside live payment threads to redirect payments, including cryptocurrency

This turned a single credential-free login into a business email compromise operation targeting finance, accounts payable, procurement, and executive staff.

What to watch for

  • A device code you did not request or expect, arriving via email or a linked page
  • Messages that push you to verify your identity by entering a code rather than signing in normally
  • Payment instruction changes that appear inside an existing email thread, especially involving new bank details or cryptocurrency
  • Pressure to act quickly on a payment or account verification request

How to build resistance

Organizations and employees can reduce exposure by treating any unsolicited device code as an immediate red flag and reporting it rather than acting on it. Because this scam abuses a legitimate Microsoft sign-in flow, technical MFA alone is not a reliable backstop, so staff need to recognize the device code pattern itself. For payment requests, verify any change to payment details through a phone call to a known number rather than by replying in the same email thread. Microsoft's Digital Crimes Unit seized 50 websites and disabled over 175 domains tied to this operation, and UK police arrested an alleged operator, but similar phishing-as-a-service kits are likely to persist, making user awareness of device code abuse and payment thread hijacking an ongoing priority.

Key findings

  • Microsoft attributed EvilTokens to “Storm-2992” and described it as a Telegram-sold phishing-as-a-service kit.
  • The operation “compromised more than 12,000 inboxes across over 10,000 organizations.”
  • Victims were lured with “AI-generated emails styled as invoices, shared documents, or voicemail notifications” containing malicious links.
  • The scam abused “device code” sign-in by showing a code on a fake page and instructing victims to enter it on Microsoft’s real site to “verify their identity,” which “authorized the attacker’s session.”
  • Post-compromise activity included registering devices in Entra ID, creating hidden inbox rules, and hijacking real payment threads to redirect payments (including crypto).
  • Microsoft’s Digital Crimes Unit “seiz[ed] 50 websites and disabl[ed] over 175 domains tied to the operation,” and UK police arrested an alleged operator on Sept. 11.

Who’s being targeted

  • Commonly targeted roles: All employees using Microsoft 365, Finance / Accounts Payable, Procurement, Executives and executive assistants, IT helpdesk / identity team.
  • Affected industries: Cross-industry (multiple organizations targeted), Finance and payments teams (BEC-focused).
  • Attack channels: email, website.
  • Impersonated: Microsoft or DocuSign (lookalike page and message), Finance staff, vendor, or executive (inside an existing email thread).

Red flags to watch for

  • You are asked to enter a device code you did not request
  • The message pushes you to “verify” via a code rather than normal sign-in
  • A link leads to a page that immediately shows a code and instructions to use Microsoft’s login page
  • Payment destination changes requested inside an email thread
  • Pressure to act quickly on payment instructions
  • Payment details changed without out-of-band verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is device code phishing?

It is a technique where an attacker starts a Microsoft device code sign-in flow and tricks a victim into entering that code on Microsoft's real login page, which authorizes the attacker's session instead of the victim's device.

Does MFA stop device code phishing?

No. Because the authentication happens on Microsoft's legitimate infrastructure, MFA was bypassed entirely in the EvilTokens campaign, and attacker access tokens survived password resets.

How did EvilTokens attackers redirect payments?

After compromising mailboxes, attackers registered devices in Entra ID, created hidden inbox rules, and impersonated finance staff, vendors, or executives inside live payment threads to redirect payments, including cryptocurrency.

How many organizations were affected by EvilTokens?

The operation compromised more than 12,000 inboxes across over 10,000 organizations before Microsoft's Digital Crimes Unit seized 50 websites and disabled over 175 domains tied to it.

Read the video transcript

Twelve thousand inboxes got hit by this: a fake invoice email that ends up authorizing an attacker on Microsoft’s real login page. You click, land on a fake Microsoft or DocuSign page, and it shows a device code. It tells you: ‘Go to microsoft.com/devicelogin and enter this code to verify your identity.’ When you do, you’ve just authorized EvilTokens’ session, no password stolen, MFA bypassed. From there, Storm-2992 used EvilTokens to sit in real mailboxes, register devices in Entra ID, hide inbox rules, then jump into live payment threads pretending to be finance or a vendor and quietly swap bank or crypto details. Your move: if you ever see a device code you didn’t request, or a payment detail change by email, stop and report it to Security, do not complete it.

Similar attacks

Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026
Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
EvilTokens MFA Phish Hijacked 12,000 Inboxes

EvilTokens MFA Phish Hijacked 12,000 Inboxes

Microsoft and partners disrupted “EvilTokens,” a phishing service that helped criminals break into more than 12,000 mailboxes across 10,000+ organizations. Victims were tricked into entering an authentication code on a real Microsoft sign-in page, letting attackers capture access tokens and get…

September 23, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
EvilTokens Used AI to Supercharge Phishing Scams

EvilTokens Used AI to Supercharge Phishing Scams

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows,…

September 22, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026