A coordinated effort by Microsoft, Coinbase, and international law enforcement has dismantled EvilTokens, a Phishing-as-a-Service (PhaaS) platform that compromised over 12,000 corporate inboxes by hijacking a standard authentication protocol. The takedown exposes a systemic vulnerability in modern identity systems and underscores the urgent need for stricter controls on legitimate device-login flows.
Tracked by Microsoft as Storm-2992, the EvilTokens operation launched in early 2026 and quickly escalated its attacks. Within months, the service compromised more than 12,000 email inboxes across over 10,000 organizations. Its phishing kits bypassed traditional security by abusing the OAuth 2.0 device-code authentication flow—a legitimate method designed for signing into smart TVs or gaming consoles.
In a typical EvilTokens attack, a phishing email lured victims into entering a short code on a login portal. This granted the attackers persistent access to the victim’s account, effectively hijacking an active authentication session without needing to steal a password or bypass multi-factor authentication prompts.
This incident signals a tactical shift for cybercriminals, moving from credential theft to exploiting the authentication ecosystem itself. The integration of generative AI into these phishing kits further lowers the barrier for entry, enabling attackers to craft convincing, multilingual lures at an unprecedented scale.
In response to this evolving threat, security experts are issuing a clear directive for all organizations. The primary action is to immediately audit and restrict the use of OAuth 2.0 device-code flows. For most enterprises, this means configuring identity providers like Azure AD to disable the flow for general use, permitting it only for explicitly approved, high-priority devices like certain IoT or signage applications.
Beyond this critical step, the incident demands a layered identity security strategy. This includes implementing conditional access policies that evaluate contextual risk signals, deploying phishing-resistant credentials such as FIDO2 hardware keys, and enhancing user training to recognize sophisticated social engineering tactics.
The successful disruption of EvilTokens also provides a proven blueprint for modern defense. The collaboration combined private-sector threat intelligence and user data from Microsoft and Coinbase with law enforcement's ability to seize criminal infrastructure. This public-private partnership model demonstrates a powerful way to proactively dismantle threat actor operations.
While the takedown is a significant win, the threat remains adaptive as PhaaS platforms rapidly rebrand and shift infrastructure. The key lesson for the industry is that defense must now secure the authentication lifecycle itself. Moving forward, organizations must prioritize rigorous policy hardening, continuous monitoring, and robust cross-sector intelligence sharing to protect this new attack surface.
微軟、Coinbase及國際執法機構的聯合行動成功瓦解EvilTokens——一個透過劫持標準驗證協議、入侵超過一萬二千個企業電子郵箱的「釣魚即服務」平台。今次行動揭露現代身份驗證系統存在系統性漏洞,凸顯有必要對合法裝置登入流程實施更嚴格的監管。
被微軟標記為Storm-2992的EvilTokens攻擊行動始於2026年初,並迅速擴大攻擊規模。數月內,該服務已入侵逾一萬個組織的一萬二千多個電子郵箱。其釣魚工具組透過濫用OAuth 2.0裝置代碼驗證流程(一種專為智能電視或遊戲機登入設計的合法機制)繞過傳統安全防禦。
典型的EvilTokens攻擊中,釣魚電郵會誘騙受害者於登入門戶輸入短暫代碼,這讓攻擊者能長期存取受害者帳戶,無需竊取密碼或繞過多因素驗證提示即可有效劫持有效驗證工作階段。
事件反映網絡犯罪分子的戰術轉變——從單純竊取憑證轉向利用驗證生態系統本身的漏洞。生成式AI與釣魚工具組的結合進一步降低攻擊門檻,使攻擊者能以前所未有的規模製作具說服力的多語言誘騙內容。
針對此威脅演變,安全專家向所有機構發出明確指引。首要行動是立即審計並限制OAuth 2.0裝置代碼流程的使用。對多數企業而言,這意味著配置Azure AD等身份供應商,停用通用流程,僅允許特定高優先級裝置(如部分物聯網設備或電子告示系統)使用。
除關鍵步驟外,事件要求實施多層次身份驗證安全策略,包括實施評估情境風險信號的條件式存取策略、部署防釣魚憑證(如FIDO2實體金鑰),並加強用戶培訓以識別複雜的社會工程攻擊手段。
EvilTokens的成功瓦解同時提供現代化防禦範本。此次協作結合了微軟與Coinbase的民間威脅情報及用戶數據,配合執法機構沒收犯罪基礎設施的能力。這種公私合作模式展示主動瓦解威脅行為者運作的有效途徑。
雖然行動取得重大勝利,但隨著「釣魚即服務」平台迅速更名及轉移基礎設施,威脅仍具適應性。業界重要教訓是防禦工作現必須確保驗證生命週期本身的安全性。未來各機構須優先實施嚴格政策強化、持續監控及健全的跨行業情報共享,以保護這新興攻擊面。
