Interestana
Home/News/EvilTokens PhaaS Disrupted After Compromising 12,000 Microsoft Accounts
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

EvilTokens PhaaS Disrupted After Compromising 12,000 Microsoft Accounts

Microsoft's Digital Crimes Unit (DCU) has successfully disrupted the EvilTokens platform, a phishing-as-a-service (PhaaS) operation that compromised more than 12,000 Microsoft accounts across over 10,000 organizations. The operation, detailed in a Microsoft Security Blog post on May 23, 2024, involved sophisticated phishing techniques designed to steal credentials and session tokens, enabling threat actors to bypass multi-factor authentication (MFA) and gain unauthorized access to victim accounts. EvilTokens provided its customers with tools and infrastructure to conduct these attacks, effectively lowering the barrier to entry for cybercriminals. The platform's disruption marks a significant victory for Microsoft in its ongoing efforts to combat cybercrime and protect its users.

The EvilTokens platform operated by selling phishing kits and services that facilitated the theft of Microsoft account credentials and session tokens. These stolen tokens allowed attackers to impersonate legitimate users, bypassing security measures like MFA. The compromised accounts were utilized for various malicious activities, including financial fraud, data theft, and further network intrusions. Microsoft's investigation revealed that the threat actors behind EvilTokens were actively selling access to compromised accounts and the phishing infrastructure itself. The DCU's action involved a coordinated effort to dismantle the platform's infrastructure, seize assets, and prevent further illicit activities. This disruption is part of Microsoft's broader strategy to combat cyber threats targeting its cloud services and customer data.

The investigation into EvilTokens began after Microsoft observed an increase in sophisticated phishing attacks targeting Microsoft 365 users. These attacks often involved highly convincing fake login pages designed to mimic legitimate Microsoft authentication portals. Once credentials were stolen, attackers would then use session tokens to maintain access even if the user changed their password. This technique is particularly dangerous as it circumvents traditional password-based security. The DCU's efforts included analyzing the platform's code, tracking its financial transactions, and working with international law enforcement agencies to dismantle the criminal enterprise. The success of this operation highlights the importance of continuous monitoring and proactive threat hunting in the fight against evolving cyber threats.

Microsoft has stated that it is committed to protecting its customers from evolving threats and will continue to invest in advanced security technologies and intelligence gathering. The disruption of EvilTokens is expected to significantly hinder the activities of phishing-as-a-service operators and their customers, thereby reducing the number of compromised Microsoft accounts. The company also emphasized the importance of user vigilance and recommended that users enable MFA, use strong, unique passwords, and be cautious of suspicious emails and links. The ongoing battle against cybercrime requires a multi-faceted approach, combining technological defenses with robust law enforcement actions and user education.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next