The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU).
The phishing-as-a-service (PhaaS) operation emerged in February and was the first to support device code authentication at scale and offer cybercriminals AI-powered features for customizing lures and sifting through compromised inboxes to identify high-value targets.
In an announcement today, Microsoft said it coordinated the takedown of EvilTokens’ infrastructure, an action that involved the Health-ISAC, law enforcement, and SpyCloud, an identity threat protection company based in Austin, Texas.
