Microsoft executed a broad takedown of EvilTokens, a phishing-as-a-service operation that sold device code phishing kits to criminal operators targeting Microsoft 365 credentials. The action involved seizing 50 websites and disabling more than 150 domains used to distribute the phishing infrastructure.
Device code phishing exploits the OAuth 2.0 device authorization flow, a legitimate Microsoft feature designed for devices with limited input capabilities. Attackers abuse this mechanism by directing victims to visit legitimate Microsoft login pages and enter a device code. Once authenticated, attackers gain OAuth tokens that bypass traditional multi-factor authentication protections. These tokens grant persistent access to victim accounts without requiring passwords or triggering MFA alerts.
The EvilTokens service operated as a subscription-based threat. It provided turnkey phishing kits, hosted infrastructure, and credential harvesting backends to lower-skilled cybercriminals who lacked the technical sophistication to build their own attack infrastructure. The service dramatically lowered barriers to entry for account takeover attacks against enterprise targets. Customers paid subscription fees and received fully functional phishing pages mimicking Microsoft 365 login flows, along with backend systems to capture and manage stolen tokens.
Microsoft's disruption focused on three operational pillars. The company seized domains hosting the phishing infrastructure itself. It disabled authentication mechanisms used to manage the service backend. It also worked with upstream infrastructure providers to identify and block hosting accounts associated with the operation. The coordinated takedown targeted the supply chain of the phishing ecosystem rather than individual phishing campaigns.
This represents a shift in Microsoft's enforcement approach. Rather than pursuing criminals conducting individual attacks, the company targeted the service provider enabling mass-scale account compromise. By removing the platform, Microsoft eliminated the distribution mechanism used by hundreds of downstream threat actors. This creates friction for attackers who must now rebuild infrastructure or find alternative platforms.
The disruption carries operational limits. Criminal operators can rebuild phishing infrastructure quickly using bulletproof hosting providers and domain registration services that operate outside U.S. jurisdiction. New domain registrations cost minimal amounts and automated deployment systems allow rapid reconstruction. The takedown imposes delays and costs on threat actors but does not permanently eliminate the threat model.
EvilTokens operated across multiple geographies, with infrastructure distributed across various hosting providers. Some infrastructure remained operational in jurisdictions where U.S. law enforcement cooperation remains limited. Microsoft's actions dismantled the primary distribution channels but did not recover all hosting infrastructure worldwide.
Device code phishing continues to affect enterprise environments. Organizations should implement conditional access policies restricting token usage to expected device types and geographic locations. Monitoring for suspicious device code authentication flows provides early detection of account compromise attempts. User awareness training specifically addressing device code flows helps employees recognize suspicious login requests.
Microsoft coordinated this disruption with law enforcement and international partners. The action demonstrates increased coordination between technology companies and authorities targeting phishing-as-a-service operations. Future actions likely target other service providers offering turnkey attack infrastructure to criminals.
