Global Enforcement Disrupts Device-Code Phishing Service Affecting 10,000 Organizations

www.news4hackers.com-global-enforcement-disrupts-device-code-phishing-service-affecting-10-000-organizations-global-enforcement-disrupts-device-code-phishing-service-affecting-10-000-organizations

A coordinated international effort led by Microsoft has dismantled the operational framework of EvilTokens, a commercial phishing platform that infiltrated over 12,000 email accounts across more than 10,000 organizations globally.

Coordinated International Effort

The operation, authorized by a U.S. court order, resulted in the seizure of 50 websites and the deactivation of 150 associated domains used to execute device-code phishing campaigns. Key collaborators included Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Health-ISAC, The Shadowserver Foundation, and TRM Labs. Two individuals, aged 32 and 38, were detained in the United Kingdom on September 11, 2026, in connection with the scheme, which Microsoft internally labels as Storm-2992.

Device-Code Phishing Bypasses Standard Authentication Mechanisms

First identified by cybersecurity researchers in March 2026, EvilTokens functioned as a phishing-as-a-service platform. Attackers exploited legitimate login interfaces to trick users into authorizing access without entering credentials. This method allowed adversaries to obtain active session tokens directly, granting them persistent access to compromised inboxes. Once infiltrated, operators established covert forwarding rules to maintain long-term control over targeted mailboxes.

Artificial Intelligence Enhances Scalability of Financial Fraud

A critical feature of the platform was an AI-driven chatbot designed to analyze breached email accounts for high-priority targets. The system systematically reviewed internal communication threads to identify employees authorized to initiate financial transfers, scrutinized vendor invoices, and mapped routine payment processes. Using predefined prompts, the software mapped organizational hierarchies, located ongoing discussions about wire transfers, and pinpointed executives whose identities could be mimicked in subsequent scams. The AI also translated and condensed internal correspondence, generating deceptive messages that blended seamlessly with existing professional exchanges. Investigators noted that significant portions of the EvilTokens codebase were developed using AI tools, lowering the technical barriers for cybercriminals to execute large-scale business compromise attacks. Additionally, the operators masked malicious traffic by leveraging trusted cloud infrastructure providers, including Vercel, Cloudflare Workers, and AWS Lambda, while employing fake CAPTCHA challenges and multi-stage redirects to bypass corporate security measures.

Commercial Infrastructure Traced Through Cryptocurrency Transactions

EvilTokens operated as a structured commercial enterprise with tiered pricing models. Its offerings included the B2B Sender at $600, the SMTP Sender at $1,000, and the Office 365 Capture Link, which hosted the primary device-code exploitation toolkit, priced at $1,500. Subscribers were required to pay a monthly $500 fee to retain access to administrative panels and active phishing kits. Coinbase’s financial analysis revealed approximately $1.1 million in revenue generated by the platform between October 2025 and June 2026, funneled through four Tron addresses. Analysts documented over 1,000 individual payments from more than 700 unique cryptocurrency addresses, highlighting the platform’s extensive commercial adoption prior to the enforcement action.

Conclusion

The operation underscores the evolving sophistication of phishing attacks, which now combine automated AI capabilities with commercialized infrastructure to target enterprises at scale. The disruption of EvilTokens represents a significant setback for cybercriminals leveraging device-code phishing to exploit organizational vulnerabilities.



About Author

en_USEnglish