MalwareSep 22, 2026
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft disrupts EvilTokens phishing service, seizing 50 websites and disabling 150+ domains.
Summary
Microsoft disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts, by seizing 50 websites and disabling over 150 domains. The operation targeted the infrastructure used to conduct device code phishing attacks against enterprise users. This coordinated takedown reflects Microsoft's efforts to dismantle high-impact credential theft operations.
Indicators of Compromise
- malware — EvilTokens
Entities
Microsoft (vendor)EvilTokens (campaign)Microsoft 365 (technology)