Threat reportPhishingTL-2026-2873

EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)

highMONITORING

EvilTokens (Storm-2992) (TL-2026-2873), also tracked as EvilTokens, is a high-severity phishing campaign, first published 2026-10-03. It is attributed to Storm-2992 with medium confidence, affects Microsoft Microsoft 365 / Microsoft Entra ID (OAuth device code flow), maps to 12 MITRE ATT&CK techniques (T1087.004, T1098.005, T1114.002), and is covered by 9 detection rules and 11 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
1Storm-2992
Detection rules
9SPL · KQL · Sigma
IOCs
11Indicators of compromise

Key facts for TL-2026-2873

Threat ID
TL-2026-2873
Also known as
EvilTokens
Severity
HIGH
Status
MONITORING
Category
PHISHING
First published
Last reviewed
Attribution
Storm-2992
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
wholesale-distribution, construction, finance, real-estate, education, health
Target regions
united states of america, canada, united kingdom, australia, india, france
Detection rules
9
Indicators of compromise
11

Malware and tooling in EvilTokens (Storm-2992)

Malware and tooling: EvilTokens, Storm, telegram, Antibot redirector, B2B Sender, SMTP Sender

How EvilTokens (Storm-2992) works

EvilTokens was a Telegram-sold phishing-as-a-service platform (Storm-2992) pairing OAuth device-code phishing kits with an AI chatbot that mines compromised Microsoft 365 inboxes for invoice and payment-fraud opportunities; it was linked to 12,000+ inboxes across 10,000+ organizations before Microsoft's Digital Crimes Unit disrupted it in September 2026. TRM Labs also reports a Feb-Aug 2026 AI-presenter YouTube 'trading bot' scheme that drained 274.60 ETH from 224 victims, and rising AI-enabled fraud (FBI IC3: 22,364 AI-related complaints, ~USD 893M in 2025).

EvilTokens appeared in February 2026 as a subscription phishing-as-a-service offering advertised on Storm-2992's Telegram channels (customer support, tutorials, crypto referral rewards). Pricing was a USD 1,500 initiation fee plus USD 500 per month, with add-ons (Antibot redirector, B2B Sender, SMTP Sender) sold separately. The kit used OAuth device-code phishing: a script requests a live device code from the Microsoft identity platform, lures the victim to the legitimate microsoft.com/devicelogin page to enter it, and a backend function (checkStatus()) polls every 3-5 seconds until the victim authenticates, handing the operator tokens without ever seeing a password. Delivery used 44 lure themes (invoices, RFPs, shared files, construction bids, compensation/benefits documents, password-expiration notices), multi-stage image links and redirect chains through compromised domains, fake CAPTCHA pages, automatic clipboard code copying, and hosting on Cloudflare Workers (workers.dev), Vercel (vercel.app), AWS Lambda and Bunny CDN. The kit supported token auto-refresh, Telegram keyword alerts on victim inboxes, and Microsoft Graph reconnaissance to map organizational structure.

The differentiator was an AI chatbot that read compromised mailboxes to identify vendor invoices, payment approvals and the people best placed to move money, with preset prompts for wire-transfer conversations and impersonation strategies; the platform also generated phishing emails with AI and was reportedly partially 'vibe coded'. Microsoft observed post-compromise email exfiltration, malicious inbox rules, new-device registration to obtain a Primary Refresh Token (within about 10 minutes in observed cases), deep reconnaissance of financial and executive accounts, and internal phishing relayed to trusted contacts. Targeted industries were wholesale distribution, construction, financial services, real estate, higher education and healthcare, concentrated in the US, Canada, UK, Australia, India and France.

On 2026-09-11 the UK Metropolitan Police cybercrime team arrested two men (aged 32 and 38; released on bail) on suspicion of making articles for use in fraud and money laundering. In September 2026 Microsoft and Health-ISAC, under authorization from the US District Court for the Eastern District of Virginia, seized 50 websites and disabled 150+ additional domains, working with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs (which mapped crypto flows toward downstream cash-out points). It was Microsoft DCU's 40th court-authorized disruption and its first against an end-to-end AI-enabled cybercrime service.

The TRM Labs article (2026-10-02) places this in a wider AI-crime context: FBI IC3 reported 22,364 AI-related complaints and nearly USD 893M in AI-tied losses in 2025 (of nearly USD 21B total reported losses); 2026 deepfake scam losses were reported as already exceeding 2025 by 263%; and an AI-generated YouTube scheme between February and August 2026 took 274.60 ETH from 224 victims by walking them through building a 'crypto trading bot' that was in fact a drainer contract they deployed themselves. The article cites Deepfake-Eval-2024, in which detector accuracy fell to 50% (video), 48% (audio) and 45% (images) versus academic benchmarks, and TRM's AI Crime Adoption Index rising from 28 (2024) to 54 (2026), with scams and fraud the only 'Mature' category. No CVEs, hashes, IP addresses or wallet addresses are published in the sources.

MITRE ATT&CK techniques used in TL-2026-2873

Discovery

T1087.004 Account Discovery: Cloud Account

Persistence

T1098.005 Account Manipulation: Device Registration

Collection

T1114.002 Email Collection: Remote Email Collection

Execution

T1204.001 User Execution: Malicious Link

Credential Access

T1528 Steal Application Access Token

Lateral Movement

T1534 Internal Spearphishing

lateral-movement

T1550.001 Use Alternate Authentication Material: Application Access Token

Defense Evasion

T1564.008 Hide Artifacts: Email Hiding Rules; T1684.001 Impersonation

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.006 Acquire Infrastructure: Web Services

Impact

T1657 Financial Theft

Affected products and versions in EvilTokens (Storm-2992)

  • Microsoft — Microsoft 365 / Microsoft Entra ID (OAuth device code flow)
    Vulnerable versions: Tenants permitting device code flow

Remediation for EvilTokens (Storm-2992)

Immediate actions

  • Hunt for anomalous OAuth device code authentication and token exchanges following device-code sign-ins
  • Revoke refresh tokens for suspected victims via revokeSignInSessions and temporarily disable the account, since access tokens remain valid for about an hour
  • Review mailboxes for malicious inbox rules, unexpected Entra device registrations and anomalous Microsoft Graph activity

Workarounds

  • Block the device code flow via Conditional Access except for accounts that need it, such as Teams device resource accounts
  • Block legacy authentication via Conditional Access

Longer-term hardening

  • Enforce phishing-resistant authentication (FIDO2 security keys, Microsoft Authenticator passkeys)
  • Apply sign-in risk Conditional Access policies that force MFA
  • Set Defender for Office 365 anti-phishing Advanced Phishing Threshold to 2-3, enable Safe Links and Zero-hour Auto Purge
  • Train finance and accounts-payable staff to verify wire-transfer and invoice changes out-of-band

Timeline of EvilTokens (Storm-2992)

  • AI-generated YouTube 'crypto trading bot' tutorial scheme begins; victims are walked through deploying drainer contracts themselves (February-August 2026).
  • EvilTokens phishing-as-a-service with AI chatbot appears (February 2026), sold via Storm-2992 Telegram channels for USD 1,500 plus USD 500 per month.
  • YouTube trading-bot scheme window closes (August 2026) with 274.60 ETH taken from 224 victims.
  • UK Metropolitan Police cybercrime team arrests two men (ages 32 and 38) on suspicion of making articles for use in fraud and money laundering; both released on bail.
  • Microsoft Threat Intelligence publishes the device-code phishing analysis, attributing the service to Storm-2992 and listing Defender detections and mitigations.
  • Microsoft DCU and Health-ISAC announce court-authorized (E.D. Va.) disruption: 50 sites seized, 150+ domains disabled, with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver and TRM Labs.
  • TRM Labs publishes 'How Law Enforcement Uses AI to Fight AI-Enabled Crime', covering EvilTokens, the YouTube drainer scheme, FBI IC3 2025 AI losses and the AI Crime Adoption Index.

Sources cited for EvilTokens (Storm-2992)

Detection coverage for TL-2026-2873

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2873 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
11 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2873

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats