EvilTokens takedown shows why cybercrime platforms are getting harder to stop
EvilTokens takedown shows why cybercrime platforms are getting harder to stop
AI coding tools, blockchain infrastructure, and low replacement costs are helping phishing-as-a-service operators rebuild faster after disruptions.
Key takeaways
- Microsoft linked EvilTokens to more than 12,000 compromised Microsoft 365 inboxes across over 10,000 organizations.
- The platform used device code phishing to abuse legitimate authentication workflows and bypass common protections.
- AI coding tools can help cybercriminals replace disrupted infrastructure faster and at a lower cost.
- Takedowns remain valuable, but lasting disruption requires coordinated action against the broader criminal ecosystem.
Microsoft’s disruption of the EvilTokens phishing-as-a-service platform highlights a growing challenge for defenders: Cybercrime infrastructure may be getting easier to rebuild than it is to dismantle. AI-assisted development, inexpensive infrastructure, and increasingly decentralized services are enabling criminal groups to recover quickly when individual platforms are taken offline.
What was the EvilTokens phishing-as-a-service platform?
The latest example is EvilTokens, a phishing-as-a-service (PhaaS) platform shut down by Microsoft. Discovered in February, the platform was linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide, with victims concentrated in the United States, Canada, the United Kingdom, France, Australia, and India.
EvilTokens was a phishing-as-a-service platform used primarily to launch device code phishing attacks. These attacks abuse a legitimate OAuth workflow designed for devices with limited interfaces, such as smart TVs, printers, and conferencing systems. Users receive a short code and enter it in a browser on a separate device to complete authentication.
Because authentication is completed on a separate device, the session initiating the request is not strongly bound to the user’s original context. As a result, cybercriminals are able to evade multifactor authentication (MFA) or employ social engineering techniques to disguise the legitimate device code flow approval as something else.
How is AI helping cybercriminals rebuild infrastructure?
The issue that has arisen is that it appears that elements of the EvilTokens platform appear to have been constructed using artificial intelligence (AI) coding tools that make it possible for cybercriminals, much like any other application developer, to instantly generate code. As such, it’s become much less difficult for cybercriminals to spin up another platform to replace one that might have been taken down.
More troubling still, cybercriminals are now starting to make use of blockchain infrastructure that makes it much more difficult to determine what IT infrastructure is actually being used to launch a cyberattack. The end result is that while it might become more difficult to discover the IT infrastructure, the cost of replacing it if it is detected continues to significantly decline. Cybercriminal syndicates are, in effect, learning how to become more resilient.
Are cybercrime platform takedowns still effective?
Takedowns of the infrastructure used by cybercriminals still makes for good cybersecurity theatre. However, as Federal agents learned during the prohibition era in the U.S., for every warehouse discovered there were 10 more being used to distribute a wide variety of alcohol. No amount of destroying the contents of a warehouse stemmed the tide any more than a takedown of a single platform used to distribute malware. A much more concerted effort to stop that later scourge will be required.
Hopefully, one day soon in the AI era it will become a lot simpler to take down multiple platforms at once. In the meantime, however, the cybercriminal syndicates are likely to have an advantage that will continue to make cybersecurity a game of Whack-A-Mole that, for now, remains extremely difficult to ultimately win once and for all time.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.