$ techbeacon▋
Phishing

Microsoft Takes Down EvilTokens Phishing Service, Seizes 50 Sites and Over 150 Domains

Microsoft Takes Down EvilTokens Phishing Service, Seizes 50 Sites and Over 150 Domains

Microsoft announced a coordinated takedown operation that resulted in the seizure of 50 websites and the disabling of more than 150 domain names linked to a phishing‑as‑a‑service platform dubbed EvilTokens. The service specialized in exploiting the device code authentication flow to hijack Microsoft 365 accounts, a tactic that allowed attackers to gain persistent access to corporate email, Teams, SharePoint and other cloud resources.

EvilTokens operated by presenting victims with a counterfeit sign‑in page that prompted them to enter a short device code generated by the legitimate Microsoft authentication process. Once the code was entered on the malicious site, the attackers could retrieve an access token on behalf of the user, effectively bypassing standard password checks. The model was sold to other cybercriminals, turning a single exploit into a rentable service that could be deployed against thousands of organizations.

The recent disruption was a joint effort involving Microsoft’s internal security teams, external partners and law‑enforcement agencies. By targeting the underlying infrastructure—registrar accounts, hosting providers and command‑and‑control servers—Microsoft was able to dismantle the network that supported the service. The operation not only removed the public‑facing phishing portals but also cut off the channels through which the malicious tokens were distributed, rendering the current iteration of EvilTokens inoperable.

Security analysts say the takedown underscores a growing trend in cybercrime: the commercialization of sophisticated phishing tools. Phishing‑as‑a‑service lowers the barrier to entry for less‑skilled actors, allowing them to launch credential‑theft campaigns without developing their own code. For enterprises that rely heavily on Microsoft 365, the threat is especially acute because a single compromised token can grant broad access to sensitive data across multiple applications.

Microsoft urged organizations to review their authentication practices, emphasizing the importance of multi‑factor authentication, conditional access policies and user education about unsolicited sign‑in prompts. The company also indicated that it will continue to monitor the ecosystem for similar services and work with partners to disrupt them swiftly. While the EvilTokens operation has been crippled, the broader phishing‑as‑a‑service market remains active, suggesting that further collaborative takedowns will be necessary to protect cloud users.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related