Unmasking EvilTokens: Getting to the root of device code phishing
Executive Summary
EvilTokens has emerged as a leading PhaaS platform that facilitates device code phishing by using AI‑generated lures, automated infrastructure, and token theft. Microsoft Digital Crimes Unit (DCU) partnered with other entities to disrupt EvilTokens’ infrastructure and operations, effectively shutting down its phishing capabilities.
Intelligence Metadata - Source Publisher: Microsoft Security - Published Date: 2026-09-22T15:00:00+00:00 - Category: threat-intel
Original Description: EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.
"Yesterdays home runs don't win today's games."
— Babe Ruth