Microsoft dismantles EvilTokens: 12,000 accounts compromised in 10,000 companies
The Digital Crimes Unit (DCU) of Microsoft has coordinated an international operation that led to the disruption of the EvilTokens platform, a phishing-as-a-service (PhaaS) service that compromised over 12,000 Microsoft accounts in more than 10,000 global organizations. This systemic attack hit critical sectors such as wholesale distribution, construction, financial services, real estate, universities, and healthcare.
Quick Response
What is EvilTokens and why is it dangerous?
- EvilTokens is a PhaaS service that exploits two-factor authentication (MFA) to steal access tokens
- It compromised 12,000 accounts in 10,000 companies in 79 countries
- It uses AI to identify high-value targets in compromised email boxes
- It was the first service to support device code authentication on a large scale
- It contributed to a 3,700% increase in device code phishing attacks in 2024
Innovative technique and large-scale impact
EvilTokens represents a turning point in the landscape of modern phishing due to its ability to bypass multi-factor authentication (MFA) by exploiting Microsoft's OAuth 2.0 device authorization flow, designed for devices with limited input capabilities such as smart TVs and printers. This approach made it possible to compromise protected accounts without having to steal credentials, a method that has seen exponential growth this year with at least 10 similar platforms active by April.
Police operation and arrests in the UK
The joint operation led to the arrest of two suspected site administrators, aged 32 and 38, in the United Kingdom. The Metropolitan Police Service executed search warrants in Canary Wharf and Nine Elms, then released the suspects on bail pending further investigation. "We remain committed to pursuing those who facilitate criminal functions and think they can remain unpunished," said Detective Inspector Serena D'Adamo.
Structure and functionality of the criminal service
EvilTokens offered access to the service for $500 per month or $1,500 one-time, with options such as B2B sending tools and SMTP and a tool for capturing Office 365 links. The service included 44 customizable phishing kits that imitated document signing platforms, cloud services, and billing systems. The attacks began with emails with variable subjects, from construction offers to password expiration notices, containing stolen device codes.
Evasion techniques and victim analysis
After accessing the accounts, EvilTokens used Microsoft Graph to map organizational relationships and AI tools to analyze the content of mailboxes for information about money transfers, outstanding invoices, and executive correspondence. This allowed the generation of contextually relevant business email compromise (BEC) messages. To evade detection, the service employed multi-stage redirects, PDFs, and HTML attachments, as well as fake CAPTCHA pages.
Geography of attacks and statistical data
Data recovered from SpyCloud reveals that 97.5% of compromised accounts belonged to business domains, with the United States as the most affected country, followed by Canada, Australia, the United Kingdom, and Saudi Arabia. The platform breached 8,708 accounts in 6,585 business domains in 79 countries, demonstrating an unprecedented global reach for a PhaaS service.
Limitations of the operation and residual threats
Although the operation obtained legal authorization to seize active infrastructures associated with the phishing service, it was not a complete dismantling operation. Microsoft warns that the threat remains active, although with a predictable reduction in the volume of attacks. "Clones" such as APToken are already emerging, demonstrating the resilience of this criminal business model.
Mitigation measures for organizations
To defend against these attacks, Microsoft recommends disabling device code authentication when not necessary and blocking the authentication flow whenever possible. Users should carefully verify the application they are logging into and interrupt the process if it is not the expected app. Phishing-resistant authentication methods such as FIDO2 security keys or passkeys are strongly recommended.
Regulatory and compliance implications
The incident underscores the importance of robust NIS2 compliance and DORA adaptation for affected organizations. The large-scale breach of business accounts represents a significant risk to digital operational resilience, requiring a review of security policies and possible updates to ISO 27001 certifications.
Impact on cyber insurance
The extensive compromise of business accounts could significantly influence the premiums of cyber insurance, especially for companies in the most affected sectors. Policies may require specific coverage for advanced phishing attacks, and the costs of incident response could increase, making effective breach remediation crucial.
The evolution of PhaaS services and the criminal market
The emergence of EvilTokens represents a turning point in the criminal market for PhaaS services, which has seen a 150% exponential growth over the last two years according to Group-IB data. This low-cost, high-return business model has attracted numerous criminal actors, with over 20 similar platforms active in 2024. Specialization in MFA bypass techniques has led to a 3,700% increase in device code phishing attacks, transforming this method into one of the main threats to global companies.
Impact on the financial sector and B2B transactions
The financial sector has been particularly affected, with a 40% increase in BEC fraud related to money transfers and fake invoices. Wholesale distribution companies have suffered average losses of $110,000 per incident, while healthcare institutions have faced serious breaches of sensitive data. Universities, with their complex identity ecosystems, have become privileged targets for advanced phishing attacks.
Challenges for Managed Detection and Response (MDR)
The evasion techniques used by EvilTokens pose new challenges for Managed Detection and Response (MDR) services. The ability to evade traditional detection systems through multi-stage redirects and fake CAPTCHA pages requires the adoption of advanced behavioral analysis and machine learning solutions. Companies using SOC as a Service must update their threat models to include these new techniques.
Future prospects and the rise of clones
The arrest of EvilTokens administrators does not mark the end of this threat. Platforms like APToken are already emerging as clones, demonstrating the resilience of the PhaaS model. Analysts predict that at least 5 new similar platforms will enter operation by the end of the year, focusing on critical sectors such as energy and critical infrastructure. The continuous evolution of these services requires a proactive approach to cybersecurity.
The importance of Data Loss Prevention (DLP)
The compromise of business accounts underscores the importance of implementing advanced Data Loss Prevention (DLP) solutions. These technologies can monitor and block unauthorized access to sensitive data, reducing the risk of information theft. Companies must integrate DLP into their security frameworks to protect critical data such as financial information, personal data, and intellectual property.
The role of FIDO2 security keys
FIDO2 security keys represent an effective solution against advanced phishing attacks. These technologies offer a phishing-resistant authentication method, eliminating the need for passwords and device codes. Companies should consider adopting passkeys and security keys to enhance user account security.
Implications for risk management and cyber insurance
The EvilTokens incident highlights the need for more robust risk management for companies. Cyber insurance policies must be updated to cover the costs of incident response and breach remediation related to these advanced attacks. Companies should collaborate with their insurance providers to develop customized coverage that reflects current risks.
The adoption of Zero Trust architectures
Zero Trust architectures offer a proactive approach to cybersecurity, reducing the risk of account compromise. These architectures are based on principles of continuous verification and role-based access, minimizing the impact of phishing attacks. Companies should consider adopting Zero Trust architectures to improve their security posture.
The need for advanced Security Information and Event Management (SIEM)
An advanced SIEM system is essential for detecting and responding to advanced phishing attacks. These solutions can analyze security data in real-time, identifying anomalous behaviors and potential threats. Companies should invest in SIEM technologies to improve their detection and incident response capabilities.
A resilient future
The EvilTokens incident serves as a wake-up call for companies around the world. The threat of advanced phishing is continuously evolving and requires a proactive approach to cybersecurity. Companies must adopt advanced technologies, update their security policies, and collaborate with service providers to develop customized solutions. Only through an integrated and resilient approach can organizations protect themselves from emerging threats and ensure the security of their data and systems.
Frequently Asked Questions
How much does it cost to implement Data Loss Prevention (DLP) solutions?
The costs for implementing DLP solutions vary depending on the size of the organization and specific needs. Basic solutions can start from a few thousand euros, while advanced implementations for large companies can reach hundreds of thousands of euros.
How can I protect my company from advanced phishing attacks?
To protect your company from advanced phishing attacks, it is essential to adopt phishing-resistant authentication technologies such as FIDO2 security keys, implement DLP solutions, and adopt Zero Trust architectures. Additionally, it is important to regularly train employees on best cybersecurity practices.
Which sectors are most affected by advanced phishing attacks?
The sectors most affected by advanced phishing attacks include the financial sector, wholesale distribution companies, healthcare institutions, and universities. These sectors are often privileged targets due to the value of the data they possess and the complexities of their identity ecosystems.
How can I evaluate the effectiveness of my cybersecurity program?
To evaluate the effectiveness of your cybersecurity program, you can conduct regular penetration tests and vulnerability assessments. Additionally, it is important to monitor security data through an advanced SIEM system and conduct periodic audits to identify and correct vulnerabilities.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.