Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

EvilTokens: How Phishing-as-a-Service Kit Led to the Exploitation of 12,000 Inboxes and Highlighted the Importance of AI-Generated Phishing Emails


EvilTokens, a phishing-as-a-service kit, was taken down by Microsoft, Coinbase, and law enforcement in September 2026. The kit compromised over 12,000 inboxes across more than 10,000 organizations, using AI-generated phishing emails to trick victims into granting access to their accounts. The takedown highlights the importance of staying vigilant against phishing attacks and the need for organizations to adopt robust security measures to protect their users' sensitive information.

  • EvilTokens, a phishing-as-a-service kit, was taken down by Microsoft, Coinbase, and law enforcement in September 2026.
  • The kit, operated by Storm-2992, compromised over 12,000 inboxes across more than 10,000 organizations.
  • The AI-powered phishing kit used device-code phishing, allowing less skilled criminals to run campaigns.
  • The operation was dismantled by a coalition of companies, including Microsoft's Digital Crimes Unit, Coinbase, Cloudflare, and others.
  • Coinbase played a key role in tracking the money trail, leading to the arrest of the operator.
  • Experts recommend verifying device codes, making phone calls for payment changes, and using passkeys or hardware keys.



  • EvilTokens, a phishing-as-a-service kit, was taken down by Microsoft, Coinbase, and law enforcement in September 2026. The kit, operated by Storm-2992, compromised over 12,000 inboxes across more than 10,000 organizations through device-code phishing and AI. The service, which costs $1,500 upfront and $500 per month, allowed customers to build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens.

    What made EvilTokens different was not the phishing itself, but the AI wrapped around it. Once a mailbox was open, an AI assistant sifted through the contents, mapped who controlled payments, and flagged the accounts worth targeting. This made it possible for far less skilled criminals to run campaigns that used to require real expertise.

    The technique at the core of EvilTokens is called device code phishing. It involves inserting oneself into the device code sign-in process, which is used for devices that can't handle a normal login screen. The user is then tricked into entering a code on a different device, which grants access to the account without exposing credentials.

    The gap between devices is exactly what gets abused. A fake email, styled as an invoice or a DocuSign request, sends the victim to a page that's quietly requested a real Microsoft device code behind the scenes. The victim sees the code, gets told to enter it on Microsoft's actual login page to "verify their identity," and does exactly that.

    Microsoft's Digital Crimes Unit led the legal side of the takedown, seizing 50 websites and disabling over 175 domains tied to the operation. Coinbase, Cloudflare, Health-ISAC, OpenAI, Railway, SpyCloud, and Shadowserver all contributed pieces to the takedown.

    Coinbase's part in the takedown was the least obvious. EvilTokens sold its kits for crypto and moved the proceeds through the Tron blockchain. Coinbase's Global Intelligence team followed the money trail, tracing roughly $1.1 million in revenue across four addresses, finding over 1,000 deposits from more than 700 separate wallets, and mapping the full path from payment to cash-out.

    This money trail led to a name, and the name led to an arrest. London's Metropolitan Police picked up the operator, seizing devices and evidence for examination. The investigation found that parts of the platform itself were reportedly "vibe coded," meaning the criminals used AI to help build their own criminal tooling. The irony was not lost on anyone.

    The practical response to this type of attack comes down to a few habits worth making automatic. Treat any device code you didn't request yourself as an immediate red flag, since no legitimate service asks you to "verify" anything by entering a code it sent you. Verify payment changes through a phone call to a known number, not through the email thread where the request showed up, and push toward passkeys or hardware keys wherever the option exists.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/EvilTokens-How-Phishing-as-a-Service-Kit-Led-to-the-Exploitation-of-12000-Inboxes-and-Highlighted-the-Importance-of-AI-Generated-Phishing-Emails-ehn.shtml

  • https://securityaffairs.com/199593/cyber-crime/eviltokens-made-phishing-as-a-service-look-easy-then-it-got-taken-down.html


  • Published: Wed Sep 23 06:21:34 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us