Threat reportPhishingTL-2026-2873
EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)
EvilTokens (Storm-2992) (TL-2026-2873), also tracked as EvilTokens, is a high-severity phishing campaign, first published 2026-10-03. It is attributed to Storm-2992 with medium confidence, affects Microsoft Microsoft 365 / Microsoft Entra ID (OAuth device code flow), maps to 12 MITRE ATT&CK techniques (T1087.004, T1098.005, T1114.002), and is covered by 9 detection rules and 11 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 1Storm-2992
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 11Indicators of compromise
Key facts for TL-2026-2873
- Threat ID
- TL-2026-2873
- Also known as
- EvilTokens
- Severity
- HIGH
- Status
- MONITORING
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Storm-2992
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- wholesale-distribution, construction, finance, real-estate, education, health
- Target regions
- united states of america, canada, united kingdom, australia, india, france
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in EvilTokens (Storm-2992)
Malware and tooling: EvilTokens, Storm, telegram, Antibot redirector, B2B Sender, SMTP Sender
How EvilTokens (Storm-2992) works
EvilTokens was a Telegram-sold phishing-as-a-service platform (Storm-2992) pairing OAuth device-code phishing kits with an AI chatbot that mines compromised Microsoft 365 inboxes for invoice and payment-fraud opportunities; it was linked to 12,000+ inboxes across 10,000+ organizations before Microsoft's Digital Crimes Unit disrupted it in September 2026. TRM Labs also reports a Feb-Aug 2026 AI-presenter YouTube 'trading bot' scheme that drained 274.60 ETH from 224 victims, and rising AI-enabled fraud (FBI IC3: 22,364 AI-related complaints, ~USD 893M in 2025).
EvilTokens appeared in February 2026 as a subscription phishing-as-a-service offering advertised on Storm-2992's Telegram channels (customer support, tutorials, crypto referral rewards). Pricing was a USD 1,500 initiation fee plus USD 500 per month, with add-ons (Antibot redirector, B2B Sender, SMTP Sender) sold separately. The kit used OAuth device-code phishing: a script requests a live device code from the Microsoft identity platform, lures the victim to the legitimate microsoft.com/devicelogin page to enter it, and a backend function (checkStatus()) polls every 3-5 seconds until the victim authenticates, handing the operator tokens without ever seeing a password. Delivery used 44 lure themes (invoices, RFPs, shared files, construction bids, compensation/benefits documents, password-expiration notices), multi-stage image links and redirect chains through compromised domains, fake CAPTCHA pages, automatic clipboard code copying, and hosting on Cloudflare Workers (workers.dev), Vercel (vercel.app), AWS Lambda and Bunny CDN. The kit supported token auto-refresh, Telegram keyword alerts on victim inboxes, and Microsoft Graph reconnaissance to map organizational structure.
The differentiator was an AI chatbot that read compromised mailboxes to identify vendor invoices, payment approvals and the people best placed to move money, with preset prompts for wire-transfer conversations and impersonation strategies; the platform also generated phishing emails with AI and was reportedly partially 'vibe coded'. Microsoft observed post-compromise email exfiltration, malicious inbox rules, new-device registration to obtain a Primary Refresh Token (within about 10 minutes in observed cases), deep reconnaissance of financial and executive accounts, and internal phishing relayed to trusted contacts. Targeted industries were wholesale distribution, construction, financial services, real estate, higher education and healthcare, concentrated in the US, Canada, UK, Australia, India and France.
On 2026-09-11 the UK Metropolitan Police cybercrime team arrested two men (aged 32 and 38; released on bail) on suspicion of making articles for use in fraud and money laundering. In September 2026 Microsoft and Health-ISAC, under authorization from the US District Court for the Eastern District of Virginia, seized 50 websites and disabled 150+ additional domains, working with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs (which mapped crypto flows toward downstream cash-out points). It was Microsoft DCU's 40th court-authorized disruption and its first against an end-to-end AI-enabled cybercrime service.
The TRM Labs article (2026-10-02) places this in a wider AI-crime context: FBI IC3 reported 22,364 AI-related complaints and nearly USD 893M in AI-tied losses in 2025 (of nearly USD 21B total reported losses); 2026 deepfake scam losses were reported as already exceeding 2025 by 263%; and an AI-generated YouTube scheme between February and August 2026 took 274.60 ETH from 224 victims by walking them through building a 'crypto trading bot' that was in fact a drainer contract they deployed themselves. The article cites Deepfake-Eval-2024, in which detector accuracy fell to 50% (video), 48% (audio) and 45% (images) versus academic benchmarks, and TRM's AI Crime Adoption Index rising from 28 (2024) to 54 (2026), with scams and fraud the only 'Mature' category. No CVEs, hashes, IP addresses or wallet addresses are published in the sources.
MITRE ATT&CK techniques used in TL-2026-2873
Discovery
T1087.004 Account Discovery: Cloud Account
Persistence
T1098.005 Account Manipulation: Device Registration
Collection
T1114.002 Email Collection: Remote Email Collection
Execution
T1204.001 User Execution: Malicious Link
Credential Access
T1528 Steal Application Access Token
Lateral Movement
lateral-movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Defense Evasion
T1564.008 Hide Artifacts: Email Hiding Rules; T1684.001 Impersonation
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.006 Acquire Infrastructure: Web Services
Impact
Affected products and versions in EvilTokens (Storm-2992)
- Microsoft — Microsoft 365 / Microsoft Entra ID (OAuth device code flow)
Vulnerable versions: Tenants permitting device code flow
Remediation for EvilTokens (Storm-2992)
Immediate actions
- Hunt for anomalous OAuth device code authentication and token exchanges following device-code sign-ins
- Revoke refresh tokens for suspected victims via revokeSignInSessions and temporarily disable the account, since access tokens remain valid for about an hour
- Review mailboxes for malicious inbox rules, unexpected Entra device registrations and anomalous Microsoft Graph activity
Workarounds
- Block the device code flow via Conditional Access except for accounts that need it, such as Teams device resource accounts
- Block legacy authentication via Conditional Access
Longer-term hardening
- Enforce phishing-resistant authentication (FIDO2 security keys, Microsoft Authenticator passkeys)
- Apply sign-in risk Conditional Access policies that force MFA
- Set Defender for Office 365 anti-phishing Advanced Phishing Threshold to 2-3, enable Safe Links and Zero-hour Auto Purge
- Train finance and accounts-payable staff to verify wire-transfer and invoice changes out-of-band
Timeline of EvilTokens (Storm-2992)
- AI-generated YouTube 'crypto trading bot' tutorial scheme begins; victims are walked through deploying drainer contracts themselves (February-August 2026).
- EvilTokens phishing-as-a-service with AI chatbot appears (February 2026), sold via Storm-2992 Telegram channels for USD 1,500 plus USD 500 per month.
- YouTube trading-bot scheme window closes (August 2026) with 274.60 ETH taken from 224 victims.
- UK Metropolitan Police cybercrime team arrests two men (ages 32 and 38) on suspicion of making articles for use in fraud and money laundering; both released on bail.
- Microsoft Threat Intelligence publishes the device-code phishing analysis, attributing the service to Storm-2992 and listing Defender detections and mitigations.
- Microsoft DCU and Health-ISAC announce court-authorized (E.D. Va.) disruption: 50 sites seized, 150+ domains disabled, with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver and TRM Labs.
- TRM Labs publishes 'How Law Enforcement Uses AI to Fight AI-Enabled Crime', covering EvilTokens, the YouTube drainer scheme, FBI IC3 2025 AI losses and the AI Crime Adoption Index.
Sources cited for EvilTokens (Storm-2992)
- How Law Enforcement Uses AI to Fight AI-Enabled Crime
- Unmasking EvilTokens: Getting to the root of device code phishing
- Disrupting EvilTokens: The AI Chatbot Built for Cybercrime
- TRM Labs Supports Microsoft's Disruption of EvilTokens, an AI-Powered Cybercrime Service
- Two arrested in UK after Microsoft takedown of 'Eviltokens' AI-chatbot for cybercriminals
- Microsoft, partners disrupt EvilTokens, AI-powered phishing service
Detection coverage for TL-2026-2873
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2873 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2873
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.