A phishing-as-a-service platform called EvilTokens has emerged as one of 2026’s most dangerous cybercrime tools, weaponizing a legitimate Microsoft authentication feature to silently hijack corporate email accounts at industrial scale.
Since surfacing in February 2026, the kit has compromised more than 12,000 inboxes across over 10,000 organizations worldwide, according to Microsoft Threat Intelligence, which tracks the operators behind it as Storm-2992.
EvilTokens’ signature technique abuses OAuth device code authentication, a legitimate flow built for devices without full browsers, like smart TVs or conferencing systems.
EvilTokens Phishing Kit Hijacks 12,000+ Inboxes
Normally, a user enters a short code on a separate screen to complete sign-in. Attackers exploit this by generating their own device code, then tricking victims into entering it on the real microsoft.com/devicelogin page through urgent-sounding lures like “password expiring” alerts or fake invoices.

Because the authenticating session isn’t tied to the user’s original device, the victim unknowingly hands over a valid access token without ever exposing a password.
Behind the scenes, a background script pings the attacker’s server every three to five seconds, waiting for the victim to complete sign-in, often auto-copying the code to the clipboard to reduce friction.
Storm-2992 sells EvilTokens through Telegram for $1,500 upfront plus a $500 monthly fee, bundling add-ons like antibot redirectors and SMTP senders.
The platform’s dashboard lets subscribers pick hosting infrastructure (Cloudflare Workers, Bunny, or PHP), customize landing pages across 44 themes, and deploy AI tools that draft role-specific phishing emails and automatically scan stolen inboxes for high-value targets, typically finance, executive, or administrative staff.
Once a token is captured, the kit hands attackers a full toolkit: automatic token refresh, admin-detection alerts, and Telegram notifications when keyword-flagged emails appear in a compromised mailbox.

“What makes EvilTokens genuinely alarming isn’t the phishing template it’s the automation layer. When AI handles reconnaissance and lure-writing, a single operator can run what used to require a whole crew. That’s the real shift threat intelligence teams need to plan for in 2026,” said a senior threat researcher tracking the campaign.
To dodge email gateways and sandboxes, EvilTokens routes victims through multi-stage redirects abusing trusted serverless platforms Vercel, Cloudflare Workers, and AWS Lambda so malicious traffic blends in with legitimate cloud activity. Fake CAPTCHA walls add another layer of friction against automated scanners.
After compromise, attackers move fast: some register new devices within 10 minutes to mint a Primary Refresh Token for long-term persistence, while others wait hours before creating hidden inbox rules or querying Microsoft Graph to map organizational structure and locate wire-transfer details.
Hardest-hit sectors include wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with victims concentrated in the US, Canada, the UK, Australia, India, and France.
Microsoft’s Digital Crimes Unit has already coordinated a takedown of EvilTokens infrastructure, but organizations should act independently.
Microsoft recommends blocking device code flow entirely unless required for specific Teams devices, enforcing phishing-resistant MFA (FIDO keys or Authenticator passkeys), enabling Safe Links and anti-phishing policies in Defender for Office 365, and alerting on suspicious inbox-rule creation.
Crucially, security teams should not rely solely on refresh-token revocation; access tokens can remain valid for up to an hour afterward, making temporary account disablement the safer containment step during active incidents.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.