BlackTree Security · Infrastructure · Automation · AI

EvilTokens Compromised 12,000 Inboxes and Let AI Choose the Next Victim

The most dangerous feature of EvilTokens was not its phishing page. It was what happened after the victim signed in.

Microsoft says the cybercrime service was linked to more than 12,000 compromised inboxes across over 10,000 organisations within months of appearing in February 2026. Once a token unlocked a mailbox, an AI assistant could search its contents, map roles and permissions, identify trusted relationships and recommend whom a criminal should impersonate to make fraud succeed.

Microsoft and Health-ISAC have now disrupted the service through legal and technical action. Partners seized 50 websites and disabled more than 150 additional domains, while the Metropolitan Police arrested two men on suspicion of offences connected with the alleged operation. Arrests and infrastructure seizures do not eliminate copied kits, affiliates or already stolen tokens, so defenders still need to look for the attack chain inside their own tenants.

The real Microsoft sign-in page completed the attack

EvilTokens abused Microsoft’s legitimate device-code authentication flow. That flow exists for devices such as televisions, printers and conference-room systems that cannot easily present a full sign-in experience.

The attacker initiated the flow and sent the victim a code through a lure. The victim was then directed to the genuine microsoft.com/devicelogin page. Entering the code and completing authentication authorised the attacker’s waiting session. The user could see the correct domain, use the correct password and satisfy multifactor authentication while still handing access to the wrong device.

Microsoft observed EvilTokens customers using 44 themes, including invoices, requests for proposals, shared files and password-expiry notices. Redirects through reputable cloud platforms and compromised domains helped the traffic blend into normal business activity.

AI turned mailbox access into an organisational map

Traditional business email compromise already depends on understanding trust: who approves payments, which supplier is expected to invoice, how an executive speaks and when a transaction will attract the least suspicion. That reconnaissance takes time.

EvilTokens industrialised it. Microsoft says the service used AI to identify users in financial, executive and administrative roles, examine wire-transfer details and pending invoices, and help draft messages that impersonated trusted contacts. Microsoft Graph access could also reveal organisational structure and sensitive permissions almost as soon as a token was captured.

In some cases, attackers registered a new device and obtained a Primary Refresh Token within ten minutes. Other operators waited before creating inbox rules or removing email, trading speed for stealth.

This is the deeper change. Generative AI does not need to discover a new exploit to alter the economics of intrusion. It can compress the slow human work between initial access and profitable abuse.

What Microsoft 365 defenders should change

  • Block device-code flow where it is not needed. If specific Teams or shared devices require it, scope the exception to those resource accounts and exclude device registration.
  • Detect the sequence. Correlate device-code sign-ins with token exchange, device registration, unusual Microsoft Graph activity and new inbox rules.
  • Treat the real login page as part of the lure. Train users to verify the application and the action being authorised, not only the domain in the address bar.
  • Respond to tokens, not just passwords. Revoke sessions and refresh tokens, remove unauthorised devices and authentication methods, and consider temporarily disabling the account when immediate containment matters.
  • Investigate the mailbox as a map of future victims. Identify invoices, trusted contacts and internal roles exposed through the compromised account, then warn the people most likely to receive a convincing follow-on request.

Microsoft warns that ordinary session revocation may leave existing access tokens valid for up to an hour. That is enough time for a hands-on attacker to act. Containment plans should account for the window rather than assuming the revocation button ends it instantly.

BlackTree recently covered passkey-themed social engineering that reached identity and cloud data. EvilTokens reinforces the same uncomfortable point: a security control can be technically intact while a victim is persuaded to authorise the attacker’s session.

The service has been disrupted. The business model has not. Any organisation that leaves device-code authentication broadly available while monitoring only passwords is protecting the secret attackers may no longer need.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *