Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Microsoft Security Blog featured image for Unmasking EvilTokens, an operations room with a video wall.
Photo: Microsoft. Official Security Blog featured image for Unmasking EvilTokens.

Detection

Microsoft Tracks EvilTokens Phishing Kit Behind Device Code Token Theft

Microsoft Threat Intelligence says EvilTokens, sold as phishing-as-a-service and tracked to Storm-2992, abused device code authentication to steal tokens and fuel BEC campaigns that compromised more than 12,000 inboxes worldwide.

Ava Okello, DetectionLondon5 min read

LONDON - Microsoft Threat Intelligence, Microsoft Defender Experts, and Microsoft Security Research on September 22, 2026, published a detailed breakdown of EvilTokens, a phishing-as-a-service kit that emerged in February 2026 and quickly became widely used for stealing Microsoft account tokens through abuse of the device code authentication flow.

According to the Microsoft Security Blog, the kit gave affiliates AI tools to tailor phishing lures and to analyze compromised inboxes for high-value targets. Microsoft said the platform facilitated business email compromise campaigns that compromised more than 12,000 inboxes in over 10,000 organizations worldwide. Microsoft tracks the developer and support operator behind EvilTokens as Storm-2992.

EvilTokens platform welcome page from the Microsoft Security Blog.
Photo: Microsoft. EvilTokens platform welcome page (Fig. 3) from the Security Blog.The kit's welcome page, as published by Microsoft.

Device code phishing is the core abuse. The legitimate OAuth device code flow is meant for constrained devices such as smart TVs, printers, and Teams endpoints that cannot complete a normal interactive sign-in. The user receives a short code on one device and enters it in a browser on another. Because authentication is completed away from the originating session, traditional multifactor checks on the victim's browser do not bind the threat actor's session. EvilTokens initiates the flow, presents the live code in a phishing page, and waits for the victim to paste that code at the real microsoft.com/devicelogin portal, authorizing the actor's session without handing over a password to the lure itself.

Sample device code lure beside the microsoft.com/devicelogin code entry screen.
Photo: Microsoft. Sample device code lure and microsoft.com/devicelogin flow (Figs. 8-9).A lure page next to the real device-login prompt.

Storm-2992 advertised and sold the kit on Telegram at $1,500 for the initial purchase plus $500 per month for continued panel access, with add-on products such as Antibot, B2B Sender, Office 365 Capture Link, and SMTP Sender sold for additional fees. The panel offered 44 themes for email templates and landing pages, plus deployment via Cloudflare Workers, Bunny, or PHP hosting, capture-mode options, CAPTCHA, and AI-assisted page design. Delivery used malicious URLs, PDFs, and HTML, often with multi-stage redirects through Vercel, Cloudflare Workers, and AWS Lambda and with fake CAPTCHA checks before the phishing content appeared.

SOCtember diagram of device-code phishing from lure to token theft.
Illustration: SOCtember. Conceptual device-code phishing to token theft chain.Lure, live code, paste at the real portal, then token theft.

Post-compromise activity, Microsoft said, included inbox rule creation, email exfiltration, Microsoft Graph reconnaissance of organizational structure and permissions, and in some cases registration of a new device within about 10 minutes to obtain a Primary Refresh Token for longer persistence. Victim activity concentrated in wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest observed concentrations in the United States, Canada, the United Kingdom, Australia, India, and France. Microsoft's Digital Crimes Unit facilitated a coordinated disruption of EvilTokens infrastructure with partners. Microsoft also noted that Huntress researchers observed EvilTokens email themes such as construction bid proposals, partnership agreements, compensation notices, and password-expiry messages.

For detection and response teams, Microsoft recommends blocking device code flow wherever possible and scoping any Teams-device exceptions tightly, including excluding the Device Registration Service resource from Conditional Access where appropriate. Other guidance covers Conditional Access and sign-in risk policies, Safe Links in Defender for Office 365, phishing-resistant MFA, and hunting for suspicious inbox rules. On confirmed or strongly suspected compromise, Microsoft advises calling revokeSignInSessions and considering a temporary account disable, because access tokens can remain valid for up to an hour after refresh-token revocation. Defender XDR and Defender for Identity detections listed in the post cover anomalous OAuth device code authentication, anomalous token exchange after device code auth, device registration after potential device-code phishing, anomalous Microsoft Graph activity after device-code phishing, and suspicious inbox rules after such sign-ins. Microsoft also published hunting queries for suspicious URL clicks correlated to Defender for Office 365 alerts and for phishing mail delivered to Inbox or Junk.

SOCtember diagram of SOC hunt signals for EvilTokens-style device code abuse.
Illustration: SOCtember. Conceptual SOC hunt signals drawn from Microsoft Defender XDR guidance.Device-code auth, token exchange, device registration, and inbox or Graph activity.

Sources:


Ava Okello covers detection engineering, EDR telemetry, and SOC hunting for SOCtember from London.

Related stories

Detection desk