EvilTokens Used Device-Code Phish + AI for BEC

CSO Online · High sophistication
Last updated September 22, 2026

Microsoft disrupted EvilTokens, a phishing-as-a-service operation linked to thousands of compromised Microsoft 365 inboxes. The group used “device code” phishing to steal valid session tokens (not passwords) and then used an AI chatbot to scan mailboxes and help craft business email compromise (BEC) fraud based on real conversations.

Key findings

  • EvilTokens was a subscription phishing-as-a-service platform linked to “more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide.”
  • Attackers abused Microsoft’s OAuth 2.0 device-code flow to steal valid session tokens, gaining access without taking passwords.
  • Victims were tricked into using a legitimate Microsoft sign-in process: they clicked a link, received a short-lived code, and entered it on the real Microsoft device login page.
  • An AI “analyst” chatbot scanned compromised inboxes to identify payment owners, trusted relationships, and invoice/transaction opportunities for BEC-style fraud.
  • Microsoft obtained a court order and seized “50 websites” and “more than 150 associated domains”; UK police arrested two suspects.

Who’s being targeted

  • Commonly targeted roles: All Microsoft 365 users, Finance / Accounts Payable, Executives, IT / Identity & Access Management, Procurement.
  • Affected industries: Wholesale distribution, Construction, Financial services, Real estate, Higher education, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Microsoft sign-in / IT login prompt, A trusted internal/external contact found in existing email threads.

Awareness takeaways

  • Treat “device code” sign-in prompts from emails as high risk; verify through known, internal IT channels before entering any code.
  • Assume a compromised mailbox will be quickly mined for payment fraud; enforce out-of-band verification for invoice, bank-change, and urgent payment requests.
  • Train finance and executives that BEC messages may be written to match real email threads and business context, not generic spam.
  • Make device-code phishing defenses a baseline (restrict device-code flow where possible and alert on unusual authentication).

Red flags to watch for

  • Being asked to enter a code after clicking a link, instead of signing in normally
  • Unusual device sign-in prompt initiated from an email link
  • Unexpected authentication workflow that feels rushed or “short-lived”
  • Payment or bank-detail changes that arrive via email only (especially in-thread)
  • Pressure to act quickly on an invoice/transaction request
  • Requests that bypass normal verification steps even though they look familiar
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: you sign in on the real Microsoft page… and that’s exactly how EvilTokens gets into your inbox. EvilTokens abused Microsoft’s OAuth 2.0 device-code flow. You click a link, see a short-lived code, then type it into the real Microsoft device login page. They don’t steal your password, they steal the access token and sit in your Microsoft 365 mailbox. Then their AI "analyst" scans your mailbox: who approves payments, which vendors you trust, which invoices are pending. It drafts BEC emails right inside real threads, same tone, same attachments, asking to change bank details or rush a payment. Your move: if an email ever tells you to enter a short device code to sign in to Microsoft, stop. Don’t enter it. Contact IT through your normal channel and ask, "Did you really send this?"

Similar attacks

EvilTokens Used AI to Supercharge Phishing Scams

EvilTokens Used AI to Supercharge Phishing Scams

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows,…

September 22, 2026
EvilTokens Takedown Exposes AI-Driven BEC Fraud

EvilTokens Takedown Exposes AI-Driven BEC Fraud

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft email inboxes across 10,000+ organizations. The service used AI to pick targets, impersonate trusted contacts, and steal session tokens so criminals could stay in…

September 22, 2026
BlackFile Crew Vishing Hits PE and Finance Firms

BlackFile Crew Vishing Hits PE and Finance Firms

Google and Reuters report a real vishing-led intrusion campaign tied to the extortion crew behind the retired “BlackFile” brand (tracked as UNC6671). Attackers call employees on personal phones spoofing the corporate IT help desk, push a same-day “passkey/MFA update,” and send them to a look‑alike…

August 12, 2026
BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

BigBear 2.0 PhaaS Steals 5,100+ M365 Logins

Researchers say the “BigBear 2.0” phishing-as-a-service operation stole over 5,100 Microsoft 365 credential records across 461 organizations by capturing passwords and session cookies. The campaign used an adversary-in-the-middle setup to bypass MFA and maintain access, with stolen data sent to…

September 8, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026