<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Storm-2992 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/actors/storm-2992/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 20:01:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/actors/storm-2992/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>EvilTokens Phishing-as-a-Service Platform Analysis</title><link>https://feed.craftedsignal.io/briefs/2026-09-eviltokens/</link><pubDate>Tue, 22 Sep 2026 20:01:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-eviltokens/</guid><description>EvilTokens is a Phishing-as-a-Service (PhaaS) platform operated by threat actor Storm-2992 that facilitates adversary-in-the-middle (AiTM) attacks by abusing OAuth device code authentication flows to compromise user accounts.</description><content:encoded><![CDATA[<p>EvilTokens is a sophisticated Phishing-as-a-Service (PhaaS) platform that emerged in February 2026, enabling threat actors to conduct large-scale business email compromise (BEC) campaigns. Managed by the actor identified as Storm-2992, the platform provides an AI-driven infrastructure to automate the delivery of phishing lures and the analysis of compromised mailboxes. The service utilizes a multi-stage delivery pipeline to bypass traditional email security gateways and targets OAuth device code authentication flows. By manipulating users into authorizing malicious device codes, attackers can effectively circumvent multifactor authentication (MFA) and gain persistent access to organizational accounts. With over 12,000 inboxes compromised across 10,000 organizations, EvilTokens represents a significant risk to cloud productivity environments. The platform's capabilities include prebuilt templates, AI-assisted target reconnaissance, and automated tools for inbox rule creation to maintain long-term persistence and exfiltrate sensitive data.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker distributes phishing emails containing malicious URLs, PDF attachments, or HTML files designed to bypass email security gateways.</li>
<li>The victim is lured to a malicious landing page that presents a deceptive device code authentication prompt.</li>
<li>The victim enters a provided short code into their browser, unknowingly authorizing an attacker-controlled session.</li>
<li>The platform captures the authorized session token, allowing the attacker to impersonate the user without possessing credentials or completing MFA.</li>
<li>The attacker performs reconnaissance within the victim's environment using Microsoft Graph to map organizational structure and permissions.</li>
<li>The attacker uses AI-assisted tools to search the compromised mailbox for high-value targets and context for further phishing lures.</li>
<li>The attacker establishes persistence by creating malicious inbox rules to conceal ongoing communications and potentially granting access to new malicious devices.</li>
<li>The attacker exfiltrates data from the compromised mailbox, continuing to operate while the stolen token remains valid.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The EvilTokens platform has impacted over 12,000 inboxes across 10,000 organizations, specifically targeting sectors such as financial services, higher education, healthcare, construction, and wholesale distribution. Successful exploitation results in account takeover, unauthorized access to sensitive corporate information via email exfiltration, and the establishment of durable persistence mechanisms that are difficult for standard security tools to detect.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following technical controls to mitigate device code phishing:</p>
<ul>
<li>Implement Conditional Access policies to strictly scope device code flow usage to authorized Teams device resource accounts only.</li>
<li>Disable the device code authentication flow organization-wide if it is not explicitly required for hardware-based conferencing solutions.</li>
<li>Configure security policies to exclude the Device Registration Service resource from any exceptions to ensure MFA enforcement.</li>
<li>Deploy spoof protections and mail flow rules to identify and block phishing messages leveraging unauthorized third-party connectors.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>phishing</category><category>cloud-security</category><category>oauth</category><category>bec</category></item></channel></rss>