OffPerimeter · Threat advisories
Campaign advisory
lowPublished 2026-09-23 · 0 indicators

Storm-2992 deploys EvilTokens PhaaS using device-code phishing on Microsoft 365 accounts

The Storm-2992 threat actor operated the EvilTokens PhaaS platform, which compromised over 12,000 Microsoft accounts across 10,000 organizations. The campaign used device code phishing to bypass MFA protections and deliver BEC attacks. Microsoft, in collaboration with law enforcement and SpyCloud, disrupted the infrastructure, though the threat remains active. The campaign targeted multiple sectors, including financial services, healthcare, and education, with the United States being the most affected country. The operation used Microsoft Graph and the OAuth 2.0 device-authorization flow to map organizational relationships and evade detection.

ShareXLinkedInWhatsApp
First seen
2026-02-01
Last seen
2026-09-22
Threat actors
Storm-2992
Malware
EvilTokens PhaaS
Sectors
Financial Services, Healthcare, Education, Telecommunications, Government, Manufacturing, Retail
Countries
United States, Canada, Australia, United Kingdom, Saudi Arabia

How it works

The campaign began with device code phishing, where attackers initiated a device-code request and sent the code to targets as part of a phishing lure. Victims were directed to a page displaying the code and a button linking to Microsoft’s legitimate login portal, where they were prompted to authenticate. Once access was gained, EvilTokens used Microsoft Graph to map organizational relationships and AI-powered tools to analyze mailbox content and identify high-value targets. To evade detection, the platform used multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages, while routing traffic through compromised sites and legitimate cloud platforms such as Vercel, Cloudflare Workers, and AWS Lambda.

Techniques (MITRE ATT&CK)

What to do

References

ShareXLinkedInWhatsApp