EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Microsoft and its partners disrupted the EvilTokens phishing-as-a-service platform, which compromised more than 12,000 Microsoft accounts across over 10,000 organizations worldwide. The operation used device-code phishing and AI-powered tools to evade MFA, target high-value inboxes, and drive business email compromise campaigns. #EvilTokens #Storm2992 #Microsoft #SpyCloud #HealthISAC

Keypoints

  • EvilTokens was disrupted by Microsoft’s Digital Crimes Unit and partners.
  • The platform compromised over 12,000 Microsoft accounts at more than 10,000 organizations.
  • It used device-code phishing to bypass MFA protections.
  • The service offered AI-powered tools and 44 customizable phishing kits.
  • Authorities arrested two suspected administrators in the United Kingdom.

Read More: https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/