Code & Chain · Signal Desk

Microsoft Takes Down EvilTokens Device-Code Phishing Service, Affecting About 12,000 Compromised Mailboxes

Original sourceInfoSec Today

Summary

Microsoft quietly took down EvilTokens, a phishing-as-a-service platform using AI to automate business email compromise (BEC), linked to about 12,000 compromised mailboxes under the threat group Storm-2992. The platform exploited the OAuth 2.0 device authorization flow to obtain verified sessions w…

Key points

  • Device-code authorization is a common breach point for account takeover without passwords, and understanding how it works can help enterprises review their own login and anomaly monitoring settings.
  • AI has pushed phishing-as-a-service toward automated target selection and customized fraud, putting more pressure on SMB BEC defenses.
  • Enterprises should re-examine OAuth device-code authorization policies and mailbox abnormal login alerts, while financial and crypto firms need to strengthen account abuse and payment authorization monitoring.

Editorial note

This page is Code & Chain's editorial summary of public sources. It may be prepared with AI assistance and published through an automated workflow. Refer to the original sources; this content is not investment, legal, or tax advice.