Azure

Microsoft DCU disrupts EvilTokens PhaaS platform behind device code phishing surge

Microsoft’s Digital Crimes Unit disrupted EvilTokens infrastructure, a top PhaaS platform using AI-assisted lures and automated token theft for device code phishing attacks.

E

Everything Cloud

Everything Cloud

Microsoft DCU disrupts EvilTokens PhaaS platform behind device code phishing surge

Microsoft’s Digital Crimes Unit disrupted EvilTokens infrastructure, a leading PhaaS platform enabling device code phishing through AI-generated lures and automated token theft. The takedown, done with partners, targets the core operations that have made EvilTokens one of the top threats in credential harvesting. This action aims to break the attack chain at its source by dismantling the infrastructure that fuels these phishing campaigns.

Microsoft

How EvilTokens scales device code phishing

EvilTokens operates as a Phishing-as-a-Service platform that specializes in device code phishing, a technique where attackers trick users into entering a legitimate device code on a sign-in page to gain access to accounts. The platform uses AI to generate convincing lures that mimic trusted communications, increasing the success rate of social engineering attempts. These lures are distributed at scale through automated infrastructure managed by the service.

Once a user enters a device code on a legitimate Microsoft sign-in page, attackers can intercept the resulting authentication token, granting them access to the victim’s account and associated cloud resources. EvilTokens automates this token theft process, reducing the need for manual intervention and enabling rapid compromise of multiple accounts. The service handles everything from lure delivery to token harvesting and exfiltration.

The platform’s infrastructure includes domains, hosting, and automation tools that are continuously updated to evade detection. Microsoft notes that EvilTokens has rapidly risen among PhaaS threats due to its efficiency and focus on exploiting device code flows, which are often less monitored than traditional password-based attacks. This combination of automation, AI, and token theft makes it particularly dangerous for organizations relying on device-based authentication.

Microsoft DCU’s disruption operation

Microsoft’s Digital Crimes Unit, in collaboration with partners, executed a disruption of EvilTokens’ infrastructure and operations. The action targeted the core systems that support the PhaaS platform, including its hosting networks, domain infrastructure, and automated attack pipelines. While specific technical details were not disclosed, the disruption aims to degrade or eliminate the platform’s ability to launch new campaigns.

The disruption is part of Microsoft’s broader strategy to dismantle cybercriminal ecosystems at the source, rather than only defending against individual attacks. By focusing on the infrastructure that enables PhaaS platforms like EvilTokens, DCU seeks to increase the cost and complexity for threat actors attempting to reuse or rebuild similar services. This approach has been used in prior takedowns of malware distribution networks and phishing kits.

Microsoft did not attribute the disruption to a specific legal action such as a seizure or court order, but emphasized that the operation was conducted with partners who have complementary authorities and capabilities. The goal is to create a sustained impact on EvilTokens’ ability to operate, forcing attackers to invest in rebuilding rather than launching new campaigns immediately. Ongoing monitoring will assess whether the disruption leads to a measurable drop in device code phishing attempts.

What defenders should do now

Organizations should review their device code authentication flows and ensure they are protected against phishing attempts that exploit this method. This includes training users to recognize suspicious requests for device codes, even when they appear to come from trusted sources. Users must be reminded that legitimate device code prompts only occur during sign-in to Microsoft services and should never be entered in response to unsolicited messages.

Enable Conditional Access policies that require phishing-resistant multi-factor authentication, such as FIDO2 security keys or Microsoft Authenticator with number matching, to reduce reliance on device code flows where possible. Monitor sign-in logs for unusual device code redemption patterns, such as multiple redemptions from unfamiliar locations or devices, which may indicate token theft in progress.

Ensure that detection rules are tuned to capture anomalies in device code usage, including impossible travel or token reuse across sessions. Leverage Microsoft Defender for Cloud Apps and Azure AD Identity Protection to detect risky sign-ins and token anomalies. While the disruption of EvilTokens reduces immediate threat volume, defenders should assume that similar PhaaS platforms will emerge and maintain vigilance against evolving social engineering tactics.

What to do next

Defenders should use this disruption as a reminder to strengthen protections around device code authentication, combining user education with technical controls like phishing-resistant MFA and anomaly detection. Review Conditional Access policies to limit device code usage where possible and monitor for abuse. Stay alert for signs of token theft and ensure response playbooks cover credential compromise scenarios. Proactive hygiene remains essential even as infrastructure takedowns disrupt specific threats.

Source: Unmasking EvilTokens: Getting to the root of device code phishing (Azure).

Share:TwitterLinkedIn

Related Articles