The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password.

The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in.

The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise.

Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide.

Affected sectors include finance, construction, healthcare and education. Microsoft saw the most victim activity in the United States, Canada, the United Kingdom, Australia, India and France.

EvilTokens Telegram bot (Source - Microsoft)
EvilTokens Telegram bot (Source – Microsoft)

Earlier coverage of EvilTokens as a phishing service traced its rapid rise, while the new findings show how stolen access feeds further scams.

The Phishing Kit That Turned Microsoft’s Login Flow

Device code sign-in was designed for equipment that cannot easily display a full login form. A person enters its short code in a browser to approve access. EvilTokens reverses the trust: the attacker starts the request, then persuades the victim to complete it.

The kit creates a fresh code when the target opens the phishing page. It can copy the code to the clipboard and direct users to Microsoft’s genuine sign-in portal.

As device code phishing attacks have shown, checking that the final login page is real does not establish who initiated the request. While the victim signs in, an automated process repeatedly checks whether the approval has gone through.

Whether the person completes password and multifactor checks or confirms an existing session, the attacker’s waiting session receives the access tokens. The phishing site never needs the password.

Microsoft says operators can then read email, search for payment details and use compromised accounts to contact colleagues or outside partners.

The kit’s AI features help draft lures tailored to a person’s job and sift through captured mail for executives, finance staff and administrators. It can also map organizational relationships to guide the next move.

Example of generated device code (Source - Microsoft)
Example of generated device code (Source – Microsoft)

That increases the value of a stolen session. Rather than sending a generic fake invoice, an attacker can study real conversations and write a request that fits an existing business relationship.

Earlier reporting on AI assisted mailbox targeting described this shift from simple account takeover toward more convincing payment fraud.

Evasion, Persistence and Defense

EvilTokens is sold to other criminals through Telegram, with a $1,500 initial price and a $500 monthly fee. Its panel offers 44 themes, redirect options and victim tracking. That packaged approach lets subscribers run campaigns without building every component themselves.

The operation can place deceptive links in images, use staged redirects and show fake verification checks before revealing the sign-in prompt. Microsoft observed thousands of short-lived automation nodes in April. These tactics make a single phishing address a poor guide to the wider operation.

Once inside, attackers may create inbox rules to hide messages or register new devices for longer-lasting access. In some cases, Microsoft saw device registration within 10 minutes of a breach. The risk resembles executive impersonation invoice schemes that rely on a plausible request reaching the right finance employee.

Example of Microsoft device code sign-in portal (Source - Microsoft)
Example of Microsoft device code sign-in portal (Source – Microsoft)

Microsoft recommends blocking device code sign-in where it is not needed and narrowly limiting exceptions where it is. Organizations should train employees not to approve codes they did not request, watch for unusual sign-ins and new inbox rules, and independently verify payment requests.

If compromise is suspected, responders should revoke refresh tokens and investigate mailbox activity. Microsoft warns that existing access tokens may remain usable for up to an hour after standard session revocation, so temporarily disabling the account can provide immediate containment while checking registered devices and hidden mail rules.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine appeared first on Cyber Security News.