# Microsoft dismantles EvilTokens, a device-code phishing service tied to about 12,000 inboxes

> Microsoft and partners took down EvilTokens, a phishing kit tied to about 12,000 hacked inboxes. How device-code phishing steals an account without a password.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-28
Canonical: https://hisnlabs.com/en/news/device-code-phishing-eviltokens

Microsoft's Digital Crimes Unit, working with Coinbase, Cloudflare, OpenAI and other partners, dismantled EvilTokens, a subscription phishing service Microsoft says compromised more than 12,000 email inboxes across over 10,000 organizations worldwide [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/). Sold on Telegram for $1,500 up front plus $500 a month, the service ran on device-code phishing, a technique that steals a working, signed-in session instead of a password and can also be aimed at Apple and Google accounts [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/).

## Background

Microsoft explains that the technique abuses a legitimate sign-in method called the OAuth device code flow, built for devices with no keyboard or browser to speak of, such as a smart TV or an office printer: the device shows a short code and a web address, a person types the code into their phone or laptop, and the device signs in without a password ever being entered on it [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/).

## Findings

Attackers turn that same flow against people. Microsoft's writeup describes a phishing page that quietly requests a fresh, real device code from Microsoft's own identity service the moment it is opened, and displays that code next to a "Continue with Microsoft" button [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/). Typing the code into the genuine microsoft.com sign-in page, as the attacker's page instructs, approves the attacker's device, not the victim's. The attacker's software checks every few seconds for up to 15 minutes to see whether this has happened, and EvilTokens copied the code straight to the clipboard to speed that up [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/). Once approved, the attacker receives a valid, signed-in session, with no password stolen and no software installed, and multi-factor authentication is sidestepped because, from the account's point of view, a real device code was legitimately approved [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/).

EvilTokens first appeared in February 2026 and grew, per Microsoft, into one of the most widely used phishing-as-a-service platforms by offering 44 phishing email and page templates, automated infrastructure on services like Vercel and Cloudflare Workers, and a Telegram bot for customer support; Microsoft tracks the operator as Storm-2992 [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/). After a mailbox was compromised, Microsoft says its AI features would sift through the stolen inbox, pick out messages about payments, map who reported to whom, and draft follow-up messages impersonating a trusted contact to push a fraudulent payment through, as The Hacker News reported [[2]](https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html).

Acting on a court order from the US District Court for the Eastern District of Virginia, Microsoft says it seized around 50 websites tied to the service and disabled more than 150 more, working with Cloudflare, OpenAI, Coinbase, SpyCloud, TRM Labs, the Shadowserver Foundation and Health-ISAC [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/). Coinbase traced roughly $1.1 million in cryptocurrency payments to the service across more than 1,000 deposits, and London's Metropolitan Police arrested two men, aged 32 and 38, in connection with running the site [[2]](https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html). TechSpot's coverage adds that victims were concentrated in the US, Canada, the UK, Australia, India and France, hitting distributors, construction firms, banks, universities and hospitals particularly hard [[3]](https://www.techspot.com/news/113952-microsoft-takes-down-eviltokens-service-used-ai-turn.html).

## Implications for Mac users

Direct exposure applies to anyone who uses a Microsoft account, work or personal, and encountered one of these phishing pages, most likely through an email about a document to sign, a password expiring, or a business proposal. The technique itself is not Microsoft-specific: Google, Apple and other services offer their own version of signing in by entering a code on another device, and the same social-engineering move works against any of them. Using a Mac does not provide protection here, because the attack targets an account in the cloud, not the computer itself.

> See what a Mac’s apps and browser are actually connecting to right now. Test FireAI free for 17 days and see every connection, app by app. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Recommendations

1. Never enter a sign-in code unless that sign-in was started personally, moments earlier, on the device being held; a code that arrives after clicking a link in an email or chat is the scam itself.
2. Be suspicious of any page that pushes toward "sign in on another device" or "continue with Microsoft/Google" right after clicking a link, especially from an unsolicited email about invoices, document signing or password expiry.
3. Slow down under urgency: EvilTokens’ templates leaned on deadlines such as an expiring password, a contract to sign, or an overdue payment.
4. Periodically check active sessions and devices in Microsoft, Google or Apple account settings, and sign out anything unrecognised.
5. Where offered, use a hardware security key instead of a code or app-based approval, since it checks the actual website address rather than a code copied by hand.

## Relevance to FireAI

Device-code phishing is not primarily a malicious app connecting from a Mac. It happens through a person’s own actions on a real, legitimate Microsoft or Google login page, and the account takeover itself happens on that company’s servers, not on the machine being used. FireAI cannot see what happens inside Microsoft’s or Google’s identity systems, cannot tell that a code was phished rather than legitimate, and cannot revoke a stolen session or token on an account; only the account provider’s own security settings and a person’s own vigilance can do that part.

Where FireAI can still help, modestly: its [threat-intelligence lists](https://hisnlabs.com/en/docs/threat-intelligence-feeds) can block a known phishing domain if reached through a link, and [Investigate](https://hisnlabs.com/en/docs/investigate-a-connection) or the [world map](https://hisnlabs.com/en/docs/world-map) can help notice a browser suddenly reaching an unfamiliar server. That is a useful extra layer, not the fix; the actual defence against this scam is refusing to enter a code that was not requested.

> While tightening up account security, take a look at what is quietly talking to the internet on a Mac: try FireAI free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

Reporting on the arrest dates varies: Microsoft-linked coverage places the London arrests between 11 and 18 September, so the exact date is unconfirmed [[2]](https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html). The roughly 12,000 compromised inboxes are all tied to EvilTokens targeting Microsoft accounts specifically; none of the sources documents a confirmed device-code phishing case against an Apple or Google account through this particular service, so that risk is described here as a property of the technique in general, not as something this takedown found evidence of [[1]](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/).

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [Microsoft Security Blog (Microsoft Threat Intelligence), 22 September 2026: Unmasking EvilTokens: Getting to the root of device code phishing](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/)
- [The Hacker News, 23 September 2026: Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises](https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html)
- [TechSpot (Skye Jacobs), 23 September 2026: Microsoft takes down EvilTokens phishing service that used AI to mine hacked inboxes for payment fraud](https://www.techspot.com/news/113952-microsoft-takes-down-eviltokens-service-used-ai-turn.html)
