Back to Feed
MalwareSep 22, 2026

Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft disrupts EvilTokens phishing service, seizing 50 websites and disabling 150+ domains.

Summary

Microsoft disrupted EvilTokens, a phishing-as-a-service platform targeting Microsoft 365 accounts, by seizing 50 websites and disabling over 150 domains. The operation targeted the infrastructure used to conduct device code phishing attacks against enterprise users. This coordinated takedown reflects Microsoft's efforts to dismantle high-impact credential theft operations.

Indicators of Compromise

  • malware — EvilTokens

Entities

Microsoft (vendor)EvilTokens (campaign)Microsoft 365 (technology)