Microsoft has disrupted a major "phishing-as-a-service" operation called EvilTokens, which it said leveraged artificial intelligence to automate attacks and compromised an estimated 12,000 mailboxes. The takedown, announced Tuesday, marks a significant move against a service that commoditized a sophisticated method for bypassing standard multi-factor authentication (MFA).

Authorized by the U.S. District Court for the Eastern District of Virginia, the action was a collaborative effort. Microsoft led the operation with support from Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver Foundation. The inclusion of OpenAI in this coalition underscores a key trend: AI is now a critical component in both the offensive and defensive cybersecurity landscape.

The core of the EvilTokens service was device-code phishing, an attack that hijacks a legitimate authentication flow. In this technique, a victim is deceived into entering a genuine authentication code—generated by the official sign-in portal—into a phishing page controlled by the attacker. This action grants the attacker's device access to the victim's account, effectively circumventing password and app-based MFA protections.

This attack method is particularly dangerous because it operates within a trusted process, making it difficult for traditional security tools to detect. According to Microsoft, the EvilTokens operators used AI to automate phishing lure generation and manage stolen sessions at scale, making the attack both efficient and widespread.

Recommended Defensive Measures for IT Administrators

This takedown is a clear signal to audit and harden identity security postures. The following layered defenses are recommended to mitigate the risk of device-code and similar phishing attacks:

  1. Migrate to Phishing-Resistant MFA: Prioritize the rollout of hardware-bound security keys (FIDO2) or passkeys. These methods are cryptographically tied to a device and cannot be phished through code entry.
  2. Enforce Granular Conditional Access: Implement policies that require trusted devices and locations for access, adding a critical layer of risk assessment beyond the credential itself.
  3. Disable Legacy Authentication: Legacy protocols often bypass modern security controls like Conditional Access and should be disabled to reduce the attack surface.
  4. Deploy Targeted User Awareness Training: Educate users specifically about the danger of entering authentication codes on untrusted websites and to verify unexpected MFA prompts.
The Strategic Implication: Beyond Static Verification

The EvilTokens incident demonstrates that defenses must evolve from simply verifying credentials at login. The emerging best practice is a model of continuous, context-aware authentication assessment, where device health, user behavior, and location are dynamically evaluated throughout a session. The collaborative takedown highlights that combating these evolving threats requires proactive, coalition-driven defense and a move away from static security postures.


微軟已瓦解一個名為 EvilTokens 的主要「釣魚即服務」操作,該服務聲稱利用人工智能自動化攻擊並入侵了估計12,000個郵箱。週二宣布的這次取締行動,標誌著對一項將繞過標準多重因素驗證(MFA)的複雜方法商品化的服務採取了重大打擊。

此次行動經美國弗吉尼亞州東區地方法院授權,是一項協作努力。微軟在健康信息共享與分析中心、Cloudflare、Coinbase、OpenAI、Railway、SpyCloud 及 Shadowserver Foundation 的支持下主導了行動。OpenAI 加入此聯盟凸顯了一個關鍵趨勢:人工智能現已成為網絡安全攻防領域的關鍵組成部分。

EvilTokens 服務的核心是裝置代碼釣魚,這是一種劫持合法認證流程的攻擊。在此技術中,受害者被欺騙將官方登入門戶生成的真實認證碼輸入由攻擊者控制的釣魚頁面。此操作使攻擊者的裝置能存取受害者的帳戶,從而有效繞過密碼及應用程式式多重因素驗證防護。

這種攻擊方法特別危險,因為它在受信任的流程內運作,使傳統安全工具難以偵測。據微軟稱,EvilTokens 操作者利用人工智能自動生成釣魚誘餌並大規模管理被盜用的會話,使攻擊既高效又廣泛。

建議IT管理員採取的防禦措施

此次取締行動清楚表明應審計並加強身份安全態勢。建議採用以下層次化防禦以緩解裝置代碼及類似釣魚攻擊的風險:

  1. 遷移至防釣魚抵抗型多重因素驗證: 優先部署硬件綁定的安全密鑰(FIDO2)或通行密鑰。這些方法通過密碼學與裝置綁定,無法透過輸入代碼進行釣魚。
  2. 實施細粒度條件式存取控制: 實施要求受信任裝置和位置才能存取的策略,增添超越憑證本身的關鍵風險評估層。
  3. 停用舊版認證: 舊版協議常繞過條件式存取等現代安全控制,應予停用以縮小攻擊面。
  4. 部署針對性用戶認知培訓: 特別教育用戶關於在不受信任網站輸入認證碼的危險,並核實意外的多重因素驗證提示。
策略意涵:超越靜態驗證

EvilTokens 事件表明防禦必須從僅在登入時驗證憑證演進。新興的最佳實踐是一種持續的、具備情境感知的認證評估模式,在整個會話期間動態評估裝置健康狀況、用戶行為和位置。此次協調取締行動強調,對抗這些演變中的威脅需要主動的、聯盟驅動的防禦,並告別靜態安全態勢。

新聞來源 / Original News Source