Simultaneously, EvilTokens employs a multi-stage delivery pipeline to bypass traditional email gateways and endpoint security through fake CAPTCHA checks and redirection chains that make use of high-reputation “serverless” platforms like Vercel, Cloudflare Workers, and AWS Lambda to blend in with legitimate enterprise cloud traffic and sidestep domain-blocklist triggers.
Statistics shared by Microsoft show that EvilTokens has been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, indicating the service had gained widespread traction among threat actors in a short span of time.
The highest concentrations of victim activity have been observed in the U.S., Canada, the U.K., Australia, India, and France. Targeted organizations include wholesale distribution, construction, financial services, real estate, higher education, and healthcare.








