Microsoft disrupted “EvilTokens,” a subscription cybercrime service that stole Microsoft account access using device-code phishing and then used AI-style automation to rapidly mine victims’ inboxes for payment and org-chart details. The goal was to quickly craft believable payment-fraud messages that appeared to come from trusted contacts, enabling invoice/bank-change scams and other business email compromise (BEC) workflows.
How the attack worked
EvilTokens was a subscription cybercrime service marketed on Telegram that offered phishing and post-compromise automation to its customers. Its first stage relied on device-code phishing: victims received phishing emails or clicked malicious attachments that led to pages running scripts communicating with Microsoft Entra in real time. These pages generated device codes and instructed victims to enter them at Microsoft's legitimate device-login site, an OAuth flow originally meant for devices with limited input options like televisions. Entering the code unknowingly authorized an attacker-controlled device, handing over account access.
Once inside a mailbox, an AI-style chatbot component analyzed the inbox at scale, identifying trusted contacts, payment approvers, reporting lines, and vendor or customer relationships. This let attackers quickly craft believable messages requesting payments or changed banking instructions, impersonating people the recipient already trusted.
Why it succeeded
The scheme worked because it exploited a legitimate, expected sign-in mechanism rather than an obviously fake login page, making the initial phishing step harder to spot. Once access was gained, the speed and scale of the automated inbox analysis meant attackers could move from compromise to convincing fraud attempts very quickly, before defenders or victims noticed anything unusual. Because the follow-on messages appeared to come from real, trusted contacts inside the victim's own mailbox history, they carried built-in credibility that generic phishing lacks.
What to watch for
- Unexpected requests to enter a device code for a sign-in you did not initiate
- Being redirected to a page that generates a code and directs you to a device-login flow
- Urgent or unclear explanations for why a new device needs authorization
- Payment or bank-detail change requests arriving by email without a verified secondary approval
- Unusual urgency or a
Key findings
- EvilTokens was marketed via Telegram and sold as a subscription service for phishing and post-compromise automation.
- The service used device-code phishing to trick users into authorizing attacker-controlled devices via Microsoft’s legitimate device-login flow.
- After takeover, an AI-style chatbot analyzed inboxes at scale to identify trusted contacts, payment approvers, reporting lines, and vendors/customers.
- The tooling helped attackers draft believable messages to request payments or change banking instructions (BEC-style payment fraud).
- Microsoft said the platform compromised 12,000 customer accounts across 10,000 organizations over several months.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Accounts Payable, Procurement/Vendor Management, Executives and payment approvers, IT/Identity and Access Management.
- Affected industries: Wholesale distribution, Construction, Financial services, Real estate, Higher education, Healthcare.
- Attack channels: email, website.
- Impersonated: Microsoft sign-in / IT sign-in prompt, A trusted business contact found in the victim’s mailbox.
Red flags to watch for
- Unexpected request to enter a device code for a sign-in you didn’t initiate
- Being redirected to a page that generates a code and tells you to use the device-login flow
- Urgent or unclear explanation of why a new device must be authorized
- Payment/bank-detail changes initiated by email without a verified secondary approval
- Unusual urgency or “new bank account” explanations
- Requests that don’t match normal approval workflows
Frequently asked questions
What is device-code phishing?
It abuses a legitimate OAuth sign-in method meant for devices with limited input, tricking victims into entering an attacker-generated code at Microsoft's real device-login site, which authorizes the attacker's device instead.
How did EvilTokens use AI after stealing account access?
An AI-style chatbot scanned compromised inboxes to identify trusted contacts, payment approvers, and reporting lines, then helped draft believable messages to request payments or change banking instructions.
Who was targeted by this scheme?
The scenarios point to all employees for the initial device-code sign-in lure, and finance, accounts payable, and payment approvers for the follow-on payment fraud attempts.
How can organizations defend against this type of attack?
Treat unexpected device-code sign-in prompts as high risk, respond quickly once an inbox compromise is suspected, and require out-of-band verification for any request to change payment details or redirect funds.
Read the video transcript
Imagine this: you enter a legit Microsoft device code… and someone else gets into your inbox. That’s EvilTokens. A Telegram subscription service that emails you a “Microsoft sign-in” link, then tells you to paste a device code into the real device-login site to “finish” sign-in. Once you do, their AI chatbot tears through your mailbox for org charts and payment approvers, then drafts super-believable emails like, “Hi, we’ve updated our bank details, please send today’s payment here instead.” Your move: if you ever see a device-code sign-in you didn’t start, or an email asking to change payment or bank details, stop and call the person on a known number before doing anything.