News · curated 22 Sep 2026
Microsoft Disrupts EvilTokens Device Code Phishing Service
First reported darkreading.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
EvilTokens illustrates how criminal phishing-as-a-service platforms are integrating AI to automate lure creation and target selection at scale, raising the volume and sophistication of business email compromise campaigns defenders must anticipate.
Microsoft and partners disrupted EvilTokens, a phishing-as-a-service platform operated by the actor tracked as Storm-2992 that provided AI-powered tools for crafting phishing lures and analyzing compromised inboxes to conduct device code phishing and business email compromise campaigns. The takedown seized 50 websites and disabled more than 150 domains; Microsoft says the platform compromised over 12,000 inboxes across more than 10,000 organizations.