Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AvisLoader Malware Adapts to Survive Server Takedowns
September 24, 2026
Konni Malware Targets Ukraine Organizations with Fake PDF Files
September 24, 2026
New Android Banking Trojan Steals PINs with AI-Generated Overlays
September 24, 2026
Home/CyberSecurity News/Phishing Kit Exploits Microsoft Login Flow for AI-Powered Fraud
CyberSecurity News

Phishing Kit Exploits Microsoft Login Flow for AI-Powered Fraud

Key Takeaways A sophisticated phishing kit, dubbed EvilTokens, is actively exploiting Microsoft’s legitimate device code login process to facilitate business email compromise (BEC). This kit,...

Marcus Rodriguez
Marcus Rodriguez
September 23, 2026 4 Min Read
11 0

Key Takeaways

  • A sophisticated phishing kit, dubbed EvilTokens, is actively exploiting Microsoft’s legitimate device code login process to facilitate business email compromise (BEC).
  • This kit, first identified in February 2026, bypasses traditional password capture by tricking users into approving an attacker’s login session.
  • Microsoft attributes these campaigns to the threat group Storm-2992, which has successfully compromised over 12,000 inboxes across more than 10,000 organizations globally.
  • EvilTokens incorporates AI capabilities to craft highly personalized phishing lures, prioritize high-value targets, and automate post-compromise activities, enhancing the effectiveness of BEC attacks.
  • Affected sectors include finance, construction, healthcare, and education, with significant activity observed in the United States, Canada, the United Kingdom, Australia, India, and France.

The Phishing Kit That Turned Microsoft’s Login Flow into an AI-Powered Fraud Machine

A new and dangerous phishing toolkit, known as EvilTokens, is being leveraged by threat actors to turn Microsoft’s standard device code sign-in procedure into a sophisticated pathway for corporate email fraud. First detected in February 2026, this kit is notable for its ability to bypass the need for victims to directly provide their passwords, instead manipulating them into unwittingly authorizing an attacker’s login attempt through a legitimate device code approval process.

Table Of Content

  • Key Takeaways
  • The Phishing Kit That Turned Microsoft’s Login Flow into an AI-Powered Fraud Machine
  • Exploiting the Device Code Flow
  • Evasion, Persistence, and Defense
  • What You Should Do

The attack typically begins with a deceptive email, often impersonating urgent communications related to invoices, shared documents, signature requests, or impending password expirations. Upon clicking a malicious link or opening an attachment, the target is directed to a page displaying a unique code and a prompt to continue the sign-in process. This interaction appears innocuous, mimicking a legitimate Microsoft login sequence.

Microsoft security researchers, who track the group behind EvilTokens as Storm-2992, have indicated that this advanced toolkit has significantly scaled business email compromise (BEC) operations. Microsoft said in a report that campaigns utilizing EvilTokens have compromised over 12,000 inboxes across more than 10,000 organizations worldwide. The widespread impact spans critical sectors including finance, construction, healthcare, and education, with the highest concentration of victims observed in the United States, Canada, the United Kingdom, Australia, India, and France.

Exploiting the Device Code Flow

The device code sign-in mechanism was originally designed to facilitate logins on devices that lack the capability to display full web-based authentication forms. Users would typically enter a short code into a separate browser on a more capable device to approve access. EvilTokens ingeniously subverts this trust model: the attacker initiates the login request, generates a valid device code, and then tricks the victim into completing the approval process, effectively authorizing the attacker’s session.

When a target accesses the phishing page, the kit dynamically generates a new device code. It can then automatically copy this code to the user’s clipboard and redirect them to Microsoft’s authentic sign-in portal. A critical aspect of this attack is that even though the victim ultimately logs into a genuine Microsoft page, they are unaware that they are approving a session initiated by an attacker. The phishing kit continuously monitors for the victim’s approval. Once the user completes their authentication, including any multi-factor authentication (MFA) challenges, the attacker’s pre-initiated session receives the necessary access tokens, entirely bypassing the need to capture the victim’s password.

With compromised access, threat actors can perform a range of malicious activities, including reading emails, searching for sensitive financial information, and using the hijacked accounts to communicate with colleagues or external partners. The kit’s integration of AI further refines these operations. It can intelligently draft highly convincing phishing lures tailored to a specific individual’s role and responsibilities. Moreover, the AI component analyzes captured email communications to identify high-value targets such as executives, finance personnel, and administrators, and maps organizational relationships to inform subsequent fraudulent activities. This capability transforms simple account takeovers into sophisticated, context-aware payment fraud schemes, significantly increasing the likelihood of success for the attackers.

Evasion, Persistence, and Defense

EvilTokens is offered as a service on Telegram, with an initial purchase price of $1,500 and a monthly subscription fee of $500. The kit provides subscribers with an administrative panel featuring 44 customizable themes, redirection options, and victim tracking functionalities, allowing even less technically proficient attackers to launch sophisticated campaigns. The operational tactics employed by EvilTokens are designed for stealth and persistence. These include embedding deceptive links within images, utilizing multi-stage redirects, and presenting fake verification checks before the actual sign-in prompt. Microsoft observed thousands of ephemeral automation nodes in April, highlighting the kit’s ability to rapidly deploy and dismantle infrastructure, making traditional IP-based blocking ineffective.

Once an account is compromised, attackers often establish persistence by creating new inbox rules to hide their activity or registering new devices for long-term access. Microsoft has noted instances where new device registrations occurred within a mere 10 minutes of initial compromise. This rapid establishment of persistence allows attackers to mimic executive impersonation and invoice fraud schemes, where plausible requests are directed to the appropriate finance employees, leveraging the trust inherent in legitimate business communications.

What You Should Do

  • Disable Unnecessary Device Code Sign-in: Organizations should restrict or entirely block device code sign-in functionality in Microsoft environments unless absolutely necessary. For required exceptions, implement stringent controls and monitoring.
  • Employee Training: Conduct regular security awareness training to educate employees about the dangers of device code phishing. Emphasize that users should never approve login codes they did not explicitly request themselves.
  • Monitor for Suspicious Activity: Implement robust monitoring for unusual sign-in patterns, new device registrations, and the creation of unexpected inbox rules. Automated alerts should be configured for such events.
  • Verify Payment Requests Independently: Establish and enforce multi-channel verification protocols for all payment requests, especially those involving changes to bank details or large sums. Never rely solely on email for confirmation.
  • Incident Response: In the event of a suspected compromise, immediately revoke all refresh tokens for the affected account. While standard session revocation can take up to an hour to propagate, temporarily disabling the account can provide immediate containment. Investigate registered devices and hidden mail rules for persistent access.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitphishingSecurity

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Fake Streaming App Exposes Android Phones to Remote Takeover

Next Post

Critical Vulnerability in Terraform Providers Exposed by Developer Tools Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Galago Ransomware Emerges, Linked to Panzer Group
September 24, 2026
Critical Check Point VPN Flaws Let Attackers Gain Remote Access Without Login
September 24, 2026
Critical Roundcube SQL Injection CVE-2023-43770 Exploited in Attacks
September 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us