Microsoft seizes 200 domains to dismantle EvilTokens after 12,000 device-code compromises
Microsoft disrupted EvilTokens, an AI platform that automated device-code phishing and BEC at scale. 12,000 accounts across 10,000 organizations were compromised before 200 domains were seized. The case shows how device code flows plus language models compress attack timelines from days to minutes.
EvilTokens launched on Telegram in February and charged $1,500 initial plus $500 monthly for an integrated workflow that automated device code authentication, inbox analysis, target selection, and BEC message drafting. The service processed victim inboxes through an AI model to surface payment approvals and trusted contacts, then generated impersonation emails. Compromises concentrated in US wholesale, construction, and financial services sectors.
Device code authentication, intended for input-limited devices, requires no password entry on the target session and bypasses standard MFA prompts when the code is entered on a secondary browser. Microsoft and SpyCloud telemetry recorded the 12,000 successful authentications over three months, with the next-highest victim counts in Canada, UK, Australia, India, and France. No public CVE was assigned; the vector relied on user interaction rather than software flaw.
The operation exposes scaling limits of prior manual BEC kits once AI reduces inbox triage from hours to minutes. Organizations using device code flows without conditional access restrictions or session binding face persistent exposure even after domain takedowns. UK Metropolitan Police arrested two suspects connected to the Telegram channel.
Microsoft has signaled expanded monitoring of device code telemetry and partner domain seizures. Enterprises should audit OAuth consent grants and restrict device code authentication to managed endpoints with additional verification.
Microsoft Threat Intelligence: monthly device-code phishing detections drop below 3,000 by March 2027 after conditional access defaults tighten.
Sources (2)
- [1]Microsoft Digital Crimes Unit disruption notice(https://blogs.microsoft.com/microsoft-security/2026/09/evil-tokens-disruption)
- [2]SpyCloud EvilTokens victim telemetry report(https://spycloud.com/research/eviltokens-2026)