How EvilTokens Exploited Device Code Flow
Microsoft has taken action against a phishing operation known as EvilTokens by seizing 50 websites and disabling over 150 domains tied to the service. The disruption was carried out through a coordinated legal and technical effort involving Microsoft’s Digital Crimes Unit and external partners. The operation targeted infrastructure used to trick users into revealing authentication credentials via device code phishing tactics. The action aims to disrupt cybercriminal activity that has been used to compromise enterprise and individual accounts globally. Microsoft stated the move is part of its ongoing efforts to defend users against evolving identity-based threats.
Latest news
YouTube is tightening rules for low-effort Shorts
Google releases Android 17 QPR 3 Beta 1 for testing
Samsung Galaxy S26 FE Slashes $40 Off Its Launch Price
Meta Launches Muse Gadgets to Bring Brain-Sensing Tech to DIY HardwareEvilTokens abused the OAuth 2.0 device code flow, a legitimate authentication method designed for devices without browsers, such as smart TVs or IoT hardware. Attackers sent fake login prompts to users, prompting them to enter codes on legitimate Microsoft pages while unknowingly granting access to attacker-controlled applications. This allowed threat actors to steal tokens and gain persistent access to email, cloud storage, and other services. The service operated as a phishing-as-a-service platform, offering tools and infrastructure to other cybercriminals for a fee. Microsoft noted that the abuse of device code flow has increased in recent months, particularly targeting organizations with weak conditional access policies.
What Makes This Disruption Significant
The seizure of 50 websites and disabling of 150 domains represents one of the larger infrastructure takedowns focused specifically on device code phishing. Unlike traditional email-based phishing, this method bypasses some common defenses by appearing as a legitimate sign-in request. Microsoft emphasized that the disruption was achieved through court orders and collaboration with domain registrars and hosting providers. The company also shared indicators of compromise with the broader cybersecurity community to help organizations detect and block related activity. Officials said the action sends a clear message that abuse of authentication protocols will not be tolerated.
Organizations are advised to monitor for suspicious device code authentication requests, especially those originating from unfamiliar locations or devices. Enforcing phishing-resistant multi-factor authentication, such as FIDO2 security keys, can reduce risk. Conditional access policies should be configured to block legacy authentication and restrict device code flow where not needed. User training should include awareness of unexpected login prompts, even if they appear on legitimate Microsoft pages. Microsoft recommends reviewing sign-in logs for patterns of device code usage that deviate from normal behavior.
How Can Organizations Protect Themselves
What is device code phishing and how does it work? Device code phishing tricks users into entering a code on a legitimate login page while unknowingly authorizing an attacker’s application. It exploits the OAuth 2.0 device code flow intended for input-constrained devices.
Frequently Asked Questions
Why did Microsoft target EvilTokens specifically? Microsoft identified EvilTokens as a phishing-as-a-service platform actively used to compromise accounts through abuse of authentication protocols, prompting legal and technical disruption.
What should users do if they suspect a device code phishing attempt? Users should not enter codes from unsolicited prompts, report the incident to their IT team, and check account activity for unauthorized access immediately.
Comments
Leave a comment