Storm-2992 deploys EvilTokens PhaaS using device-code phishing on Microsoft 365 accounts
The Storm-2992 threat actor operated the EvilTokens PhaaS platform, which compromised over 12,000 Microsoft accounts across 10,000 organizations. The campaign used device code phishing to bypass MFA protections and deliver BEC attacks. Microsoft, in collaboration with law enforcement and SpyCloud, disrupted the infrastructure, though the threat remains active. The campaign targeted multiple sectors, including financial services, healthcare, and education, with the United States being the most affected country. The operation used Microsoft Graph and the OAuth 2.0 device-authorization flow to map organizational relationships and evade detection.
- First seen
- 2026-02-01
- Last seen
- 2026-09-22
- Threat actors
- Storm-2992
- Malware
- EvilTokens PhaaS
- Sectors
- Financial Services, Healthcare, Education, Telecommunications, Government, Manufacturing, Retail
- Countries
- United States, Canada, Australia, United Kingdom, Saudi Arabia
How it works
The campaign began with device code phishing, where attackers initiated a device-code request and sent the code to targets as part of a phishing lure. Victims were directed to a page displaying the code and a button linking to Microsoft’s legitimate login portal, where they were prompted to authenticate. Once access was gained, EvilTokens used Microsoft Graph to map organizational relationships and AI-powered tools to analyze mailbox content and identify high-value targets. To evade detection, the platform used multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages, while routing traffic through compromised sites and legitimate cloud platforms such as Vercel, Cloudflare Workers, and AWS Lambda.
Techniques (MITRE ATT&CK)
- T1566.001 · initial_accessSpearphishing AttachmentThe phishing-as-a-service (PhaaS) operation emerged in February and was the first to support device code authentication at scale and offer cybercriminals AI-powered features for customizing lures and sifting through compromised inboxes to identify high-value targets.
- T1204.002 · executionMalicious FileA device code phishing attack starts with the attacker initiating a device-code request and sending the received code to a target as part of a phishing lure.
- T1112 · persistenceModify RegistryThe platform can search messages for wire-transfer information, pending invoices, and executive correspondence, then generate contextually relevant business email compromise (BEC) messages.
- T1078.001 · privilege_escalationDefault AccountsEvilTokens abuses Microsoft’s legitimate OAuth 2.0 device-authorization flow, which is designed for devices with limited input capabilities.
- T1070.004 · defense_evasionFile DeletionTo evade detection, EvilTokens uses multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages to impede automated analysis.
- T1552.001 · credential_accessCredentials In FilesThe victim is directed to a page that displays the code and a button that links to Microsoft’s legitimate login portal, where they are prompted to authenticate.
- T1046 · discoveryNetwork Service DiscoveryAfter gaining access to an account, EvilTokens uses Microsoft Graph to map organizational relationships and AI-powered tools to analyze mailbox content and identify high-value targets within the breached environment.
- T1213 · collectionData from Information RepositoriesThe platform can search messages for wire-transfer information, pending invoices, and executive correspondence, then generate contextually relevant business email compromise (BEC) messages.
- T1071.001 · command_and_controlWeb ProtocolsEvilTokens uses multi-stage redirects, PDFs, HTML attachments, and fake CAPTCHA pages to impede automated analysis, while routing traffic through compromised sites and legitimate cloud platforms such as Vercel, Cloudflare Workers, and AWS Lambda.
- T1040 · credential_accessNetwork SniffingSpyCloud’s dataset shows that EvilTokens was focused on businesses, with roughly 97.5% of compromised accounts belonging to enterprise domains.
- T1486 · impactData Encrypted for ImpactThe platform can search messages for wire-transfer information, pending invoices, and executive correspondence, then generate contextually relevant business email compromise (BEC) messages.
What to do
- Disable device-code authentication when not required to prevent exploitation of the device-code phishing technique.
- Block the device-code flow wherever possible to mitigate the risk of similar attacks.
- Verify the application being authenticated to and avoid proceeding if it is not an expected app.
- Monitor for suspicious login activity and use phishing-resistant authentication methods like FIDO2 security keys or passkeys.
- Review and update security policies to address the risks associated with device-code phishing.