At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | Storm-2992 and associated cybercrime subscribers |
| Activity Type | Phishing-as-a-Service, device code phishing, AI mailbox analysis, BEC |
| Targets or Victims | Over 10,000 organizations across healthcare, finance, and education |
| Scale | More than 12,000 compromised inboxes; $1,500 purchase plus $500 monthly fees |
| Jurisdiction / Status | US federal court civil seizure order; two suspects arrested on bail in the UK |
| Source | Microsoft Digital Crimes Unit and Threat Intelligence |
Executive Summary
Microsoft coordinated with global industry and law enforcement partners to take down the EvilTokens cybercrime platform. The criminal service combined device code phishing with artificial intelligence to compromise organizational email accounts and guide financial theft. Authorities seized dozens of operational domains and arrested two suspected operators in the United Kingdom.
What Happened
On September 22, 2026, Microsoft announced court-authorized legal and technical actions against a fast-growing cybercrime network. The operation targeted the EvilTokens cybercrime platform, which launched in February 2026. Attackers used the platform to bypass multi-factor authentication through device code phishing.
Unlike traditional credential theft, the service tricked users into completing authentication on Microsoft sign-in portals. Victims entered temporary codes generated by the attackers into legitimate web forms. As the Microsoft report observed, “By completing the normal authentication sign-in process, victims unknowingly gave criminals access to their email accounts without revealing their passwords.” This authorization generated valid OAuth access and refresh tokens.
Furthermore, the platform featured an artificial intelligence chatbot built directly into the management panel. Once criminals gained access to an account, the chatbot analyzed email message histories. It flagged financial approval threads and identified high-value targets. Preset prompt shortcuts allowed operators to map accounting personnel and locate pending invoices. In addition, the system drafted convincing messages to request urgent wire transfers.
To evade security gateways, the service used automated cloud deployment pipelines. Operators created landing pages through serverless providers like Cloudflare Workers, AWS Lambda, and Vercel. These cloud redirects masked the attack traffic behind reputable domains.
Who Is Behind It
Microsoft Threat Intelligence tracks the developer and primary operator of the service as Storm-2992 with moderate confidence. The threat group marketed the software package on Telegram through automated sales bots. Subscriptions cost an initial fee of $1,500 along with a recurring $500 monthly payment.
Investigators found evidence that the creators relied on modern coding tools to build the software suite. Multiple commercial machine learning models powered the backend analysis pipeline. As Microsoft noted, “The toolkit offered a plethora of prebuilt phishing templates and landing pages with an AI-powered assistant to aid in structuring target-specific emails.”
Law enforcement swiftly intervened to disrupt the leadership behind the operation. On September 11, 2026, the Metropolitan Police Service arrested two men aged 32 and 38 in the United Kingdom. Officers seized computer hardware and released the individuals on police bail while investigations proceed.
Impact and Scale
The platform expanded rapidly across multiple international jurisdictions within just seven months. Microsoft documented severe compromises affecting critical infrastructure and commercial businesses. According to official findings, “Within months of launching in February 2026, EvilTokens had been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, showing how quickly the service gained traction.”
Victim organizations spanned healthcare, education, financial services, construction, and wholesale supply chains. High concentrations of victims appeared across the United States, Canada, the United Kingdom, Australia, India, and France.
Once inside an account, attackers established persistence by creating hidden inbox rules. In some instances, they registered rogue devices to secure Primary Refresh Tokens. Because the platform targeted healthcare providers, Health-ISAC joined Microsoft as a co-plaintiff in federal court.
What Comes Next and Defense Guidance
The Eastern District of Virginia granted court orders allowing Microsoft to dismantle core operational servers. Working with Cloudflare, OpenAI, and cybersecurity partners, Microsoft seized 50 active websites. Additionally, the coalition disabled more than 150 supporting domains.
Organizations must adapt their identity defenses against modern session token attacks. Network administrators should block device code authentication flows for accounts that do not require them. If conference devices require the protocol, administrators must limit exceptions to designated resource accounts.
Defenders should also implement conditional access policies that enforce device compliance and trusted locations. Whenever an account compromise occurs, administrators must revoke active session tokens rather than only resetting passwords. Organizations seeking technical hunting rules should consult the Microsoft Threat Intelligence analysis of device code phishing. Finally, financial departments must verify payment modifications through out-of-band communication channels.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!