EvilTokens is a financially motivated phishing-as-a-service (PhaaS) operation, tracked by Microsoft as Storm-2992, that emerged in February 2026. It targets Microsoft 365 accounts through OAuth 2.0 Device Authorization Grant abuse, commonly called device-code phishing. Victims are induced to enter an attacker-generated code on a legitimate Microsoft authentication page and complete normal sign-in and multifactor authentication; this authorizes an attacker-controlled client and yields access and refresh tokens without requiring password capture. The service has been associated with compromise of more than 12,000 mailboxes across over 10,000 organizations worldwide. EvilTokens provides affiliates with phishing templates, centralized token and session management, mailbox access, and infrastructure-deployment capabilities. Its operators use redirect chains, attachment-based lures, CAPTCHA and anti-bot gating, compromised sites, and cloud-hosted infrastructure to evade detection. Post-compromise tooling uses Microsoft Graph to enumerate organizational relationships, contacts, mailboxes, calendars, payment workflows, and financial correspondence. AI-assisted functions summarize and translate email, identify fraud opportunities, select targets, and produce tailored business email compromise messages. The operation supports token refresh and Primary Refresh Token acquisition to sustain access, and enables activity against Microsoft 365 email, SharePoint, OneDrive, Teams, and related resources. ARToken is an affiliate or closely associated multi-tenant BEC operations panel within the EvilTokens ecosystem. It shares device-code workflow patterns and token-persistence functionality, while adding capabilities including inbox-rule manipulation, cross-mailbox keyword monitoring, token sharing and import, location-adaptive lures, anti-analysis controls, and SharePoint and OneDrive operations. EvilTokens has targeted organizations in financial services, construction, real estate, health care, wholesale trade, and higher education, with downstream activity focused on financial fraud and business email compromise. A coordinated civil and law-enforcement disruption in September 2026 seized portions of its infrastructure and led to the arrest of suspected administrators in the United Kingdom.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-as-a-Service operation that compromised more than 12,000 email accounts across 10,000 organizations globally. It used OAuth 2.0 Device Authorization Grant/device-code phishing against Microsoft accounts, then used Microsoft Graph and AI tools to analyze mailboxes and facilitate business-email-compromise attacks.
Cybercrime-as-a-service platform used to compromise email accounts, analyze inboxes with AI, identify financial conversations and trusted relationships, and facilitate business-email-compromise and financial-fraud operations.
Device-code phishing service targeting Microsoft 365 users by tricking victims into authorizing attacker-controlled sessions through Microsoft's legitimate OAuth device flow, yielding access and refresh tokens.
Phishing-as-a-Service platform abusing Microsoft OAuth 2.0 Device Authorization Grant to trick victims into authorizing attacker-controlled clients, yielding access and refresh tokens without stealing passwords directly.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.