Microsoft’s Digital Crimes Unit (DCU) says it coordinated the disruption of EvilTokens, a phishing-as-a-service (PhaaS) platform that compromised more than 12,000 Microsoft accounts across over 10,000 organizations worldwide.
The operation emerged in February and used device-code phishing to obtain authentication tokens despite multifactor authentication protections. EvilTokens also offered AI-powered tools to analyze inboxes, identify valuable targets, and create business email compromise messages. Microsoft tracks the group behind the service as Storm-2992.
The action involved Health-ISAC, law enforcement, and SpyCloud. Two men, aged 32 and 38, suspected of administering the EvilTokens website were arrested in the U.K. after information was received in August. Police executed warrants on Friday at addresses in Canary Wharf and Nine Elms. Both suspects were released on bail pending further investigation.
SpyCloud identified 8,708 compromised accounts across 6,585 corporate email domains in 79 countries. The service offered 44 customizable phishing kits and was advertised through Telegram for $500/month or a one-time fee of $1,500. Microsoft said the disruption followed legal authorization to seize active infrastructure, but the threat remains active and is expected to decline in volume.
Comments
0No comments yet. Be the first to comment.