Microsoft’s Sep 22 security blog is the primary: EvilTokens became one of the top PhaaS kits for device code authentication abuse — a legitimate OAuth flow for constrained devices that attackers turn into MFA-bypass token theft. Microsoft Threat Intelligence tracks the kit’s developer/support actor as Storm-2992. DCU, working with partners, facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service.
Impact numbers from Microsoft: BEC campaigns via the platform compromised more than 12,000 inboxes in over 10,000 organizations worldwide, with observed victim activity concentrated in the US, Canada, UK, Australia, India, and France across wholesale, construction, financial services, real estate, higher ed, and healthcare. Post-compromise tooling used Microsoft Graph recon and AI assistants to mine mailboxes for high-value BEC targets. Kit pricing on Telegram (Microsoft): $1,500 initial purchase plus $500/month; add-ons (antibot, senders, O365 capture link) billed separately. 44 lure themes.
BleepingComputer (Sep 22, 11:00 AM ET) adds partner and enforcement detail not spelled out in the Microsoft lede: coordination involved Health-ISAC, law enforcement, and SpyCloud. SpyCloud’s recaptured phished data: more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries (~97.5% enterprise domains). Two men (32 and 38), suspected EvilTokens website admins, arrested in the UK; Met Police warrants Friday in Canary Wharf and Nine Elms; both released on bail pending further investigation. BC: legal seizure of active infrastructure — not a full takedown; threat remains active, volume expected to drop; clones such as APToken already noted.
POV: disable device-code auth where unused, prefer phishing-resistant MFA (FIDO2 / passkeys), and treat unexpected microsoft.com/devicelogin prompts as hostile. Sources: Microsoft Security Blog Sep 22 (primary); partner/arrest/active-status framing per BleepingComputer Sep 22. Victim dollar losses: Undisclosed.
