EvilTokens Uses Device Codes to Bypass MFA

Microsoft Security Blog · High sophistication
Last updated September 22, 2026

Microsoft reports that the EvilTokens phishing-as-a-service platform helped criminals compromise thousands of organizations by tricking users into completing a legitimate Microsoft “device code” login. The lure drives victims to enter a short code at microsoft.com/devicelogin, which unknowingly authorizes the attacker’s session without stealing the password directly. After access, attackers steal email data and set persistence (like inbox rules or registering new devices) to stay in control.

Key findings

  • EvilTokens is described as a phishing-as-a-service platform that supported “sophisticated business email compromise (BEC) campaigns” and “compromised more than 12,000 inboxes in over 10,000 organizations worldwide.”
  • The core trick is “device code phishing flow,” where the attacker provides a device code and convinces the user to enter it at the real Microsoft device login page, authorizing the attacker’s session.
  • Lures include high-pressure themes and business pretexts (e.g., invoices, RFPs, shared files) and were observed with content such as “construction bid proposals… employee compensation/benefits, and password expiring notices.”
  • Post-compromise activity includes “email exfiltration and persistence,” including “malicious inbox rules that conceal communications” and registering new devices for “a particularly durable method to maintain persistence.”
  • Infrastructure and delivery techniques aim to evade detection using redirects and common cloud platforms: “abuse of Vercel (.vercel.app), Cloudflare Workers (.workers.dev), and AWS Lambda.”
  • Microsoft tracks the developer/support actor as “Storm-2992” and notes its sale/advertising via Telegram.

Who’s being targeted

  • Commonly targeted roles: All employees (Microsoft 365 users), Finance and Accounts Payable, Procurement, HR, Executives and executive assistants, IT/Helpdesk (for reporting and response).
  • Affected industries: Wholesale distribution, Construction, Financial services, Real estate, Higher education, Healthcare.
  • Attack channels: email, website.
  • Impersonated: Microsoft / Microsoft sign-in, A vendor or business partner (invoice/RFP/shared file) plus a Microsoft sign-in step.

Awareness takeaways

  • Treat any request to enter a “device code” as suspicious unless you personally initiated it on a trusted device (e.g., a conference room/Teams device you are setting up).
  • Be extra cautious with urgent, high-pressure emails (password expiry, invoices, RFPs, shared files) that push you to click links or open attachments.
  • If a “document” link shows verification steps (like CAPTCHA) or multiple redirects before a sign-in, stop and verify with the sender through a known contact method.
  • Report suspected compromise quickly, attackers may set stealthy inbox rules or register new devices soon after access to hide activity and stay persistent.

Red flags to watch for

  • High-pressure wording pushing immediate action (e.g., password expiring)
  • You are asked to enter a code you did not request on a separate Microsoft login page
  • Unexpected “Copy Code” / “Continue with Microsoft” flow after clicking an email link/attachment
  • Unexpected CAPTCHA/verification gate before viewing a document
  • Multiple redirects before reaching the content
  • A document-view request that turns into a Microsoft device-code login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Action Required: Password Expiration.” Looks urgent, looks Microsoft, and it wants you to click. You click, solve a quick CAPTCHA, and suddenly you’re on the real microsoft.com/devicelogin page with a short code and a big “Copy Code” button. Here’s the trap: EvilTokens uses this legit device-code flow so when you enter that code, you silently log in THEIR session. They can read your mail, hide it with inbox rules, even register new devices. If you ever see a device code you didn’t ask for, stop. Don’t enter it. Close the page and report it to Security right away.

Similar attacks

Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Device-Code Phishing Service Hit After 12K Breaches

Device-Code Phishing Service Hit After 12K Breaches

Microsoft and partners disrupted “EvilTokens,” a phishing-as-a-service platform Microsoft links to over 12,000 compromised inboxes across more than 10,000 organizations. The service used deceptive emails to trick people into pasting a “device code” into Microsoft’s real sign-in page…

September 22, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026