{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/storm-2992/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Storm-2992"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft 365","Office 365"],"_cs_severities":["high"],"_cs_tags":["phishing","cloud-security","oauth","bec"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eEvilTokens is a sophisticated Phishing-as-a-Service (PhaaS) platform that emerged in February 2026, enabling threat actors to conduct large-scale business email compromise (BEC) campaigns. Managed by the actor identified as Storm-2992, the platform provides an AI-driven infrastructure to automate the delivery of phishing lures and the analysis of compromised mailboxes. The service utilizes a multi-stage delivery pipeline to bypass traditional email security gateways and targets OAuth device code authentication flows. By manipulating users into authorizing malicious device codes, attackers can effectively circumvent multifactor authentication (MFA) and gain persistent access to organizational accounts. With over 12,000 inboxes compromised across 10,000 organizations, EvilTokens represents a significant risk to cloud productivity environments. The platform's capabilities include prebuilt templates, AI-assisted target reconnaissance, and automated tools for inbox rule creation to maintain long-term persistence and exfiltrate sensitive data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker distributes phishing emails containing malicious URLs, PDF attachments, or HTML files designed to bypass email security gateways.\u003c/li\u003e\n\u003cli\u003eThe victim is lured to a malicious landing page that presents a deceptive device code authentication prompt.\u003c/li\u003e\n\u003cli\u003eThe victim enters a provided short code into their browser, unknowingly authorizing an attacker-controlled session.\u003c/li\u003e\n\u003cli\u003eThe platform captures the authorized session token, allowing the attacker to impersonate the user without possessing credentials or completing MFA.\u003c/li\u003e\n\u003cli\u003eThe attacker performs reconnaissance within the victim's environment using Microsoft Graph to map organizational structure and permissions.\u003c/li\u003e\n\u003cli\u003eThe attacker uses AI-assisted tools to search the compromised mailbox for high-value targets and context for further phishing lures.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes persistence by creating malicious inbox rules to conceal ongoing communications and potentially granting access to new malicious devices.\u003c/li\u003e\n\u003cli\u003eThe attacker exfiltrates data from the compromised mailbox, continuing to operate while the stolen token remains valid.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe EvilTokens platform has impacted over 12,000 inboxes across 10,000 organizations, specifically targeting sectors such as financial services, higher education, healthcare, construction, and wholesale distribution. Successful exploitation results in account takeover, unauthorized access to sensitive corporate information via email exfiltration, and the establishment of durable persistence mechanisms that are difficult for standard security tools to detect.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following technical controls to mitigate device code phishing:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement Conditional Access policies to strictly scope device code flow usage to authorized Teams device resource accounts only.\u003c/li\u003e\n\u003cli\u003eDisable the device code authentication flow organization-wide if it is not explicitly required for hardware-based conferencing solutions.\u003c/li\u003e\n\u003cli\u003eConfigure security policies to exclude the Device Registration Service resource from any exceptions to ensure MFA enforcement.\u003c/li\u003e\n\u003cli\u003eDeploy spoof protections and mail flow rules to identify and block phishing messages leveraging unauthorized third-party connectors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T20:01:22Z","date_published":"2026-09-22T20:01:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-eviltokens/","summary":"EvilTokens is a Phishing-as-a-Service (PhaaS) platform operated by threat actor Storm-2992 that facilitates adversary-in-the-middle (AiTM) attacks by abusing OAuth device code authentication flows to compromise user accounts.","title":"EvilTokens Phishing-as-a-Service Platform Analysis","url":"https://feed.craftedsignal.io/briefs/2026-09-eviltokens/"}],"language":"en","title":"CraftedSignal Threat Feed - Storm-2992","version":"https://jsonfeed.org/version/1.1"}