Microsoft and its partners disrupted the EvilTokens phishing-as-a-service platform, which compromised more than 12,000 Microsoft accounts across over 10,000 organizations worldwide. The operation used device-code phishing and AI-powered tools to evade MFA, target high-value inboxes, and drive business email compromise campaigns. #EvilTokens #Storm2992 #Microsoft #SpyCloud #HealthISAC
Keypoints
- EvilTokens was disrupted by Microsoftβs Digital Crimes Unit and partners.
- The platform compromised over 12,000 Microsoft accounts at more than 10,000 organizations.
- It used device-code phishing to bypass MFA protections.
- The service offered AI-powered tools and 44 customizable phishing kits.
- Authorities arrested two suspected administrators in the United Kingdom.