AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Microsoft announced on Tuesday that it disrupted EvilTokens, an AI-powered phishing platform used by cybercriminals to target many organizations worldwide.
EvilTokens emerged in February 2026, and according to Microsoft, it has been used to compromise more than 12,000 email accounts at over 10,000 organizations, including in the US, Canada, the UK, Australia, India, and France.
The platform enabled threat actors to gain access to targeted accounts via device code phishing, which targets the device code authentication flow designed for devices that don’t support standard login methods, such as TVs and printers. The authentication process requires the user to enter a short code presented on the device into a web browser session on a separate device.
Threat actors can abuse this by initiating the authentication flow and providing the code to the targeted user via a phishing lure. If the user is convinced to complete the authentication process in a...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE