# EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)

> EvilTokens was a Telegram-sold phishing-as-a-service platform (Storm-2992) pairing OAuth device-code phishing kits with an AI chatbot that mines compromised Microsoft 365 inboxes for invoice and payment-fraud opportunities; it was linked to 12,000+ inboxes across 10,000+ organizations before Microsoft's Digital Crimes Unit disrupted it in September 2026. TRM Labs also reports a Feb-Aug 2026 AI-presenter YouTube 'trading bot' scheme that drained 274.60 ETH from 224 victims, and rising AI-enabled fraud (FBI IC3: 22,364 AI-related complaints, ~USD 893M in 2025).

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2873
- **ID:** TL-2026-2873
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** MONITORING
- **Actor:** Storm-2992
- **Detections:** 9 · **IOCs:** 11 (full data via the Threadlinqs MCP server — Purple tier)

## Description

EvilTokens appeared in February 2026 as a subscription phishing-as-a-service offering advertised on Storm-2992's Telegram channels (customer support, tutorials, crypto referral rewards). Pricing was a USD 1,500 initiation fee plus USD 500 per month, with add-ons (Antibot redirector, B2B Sender, SMTP Sender) sold separately. The kit used OAuth device-code phishing: a script requests a live device code from the Microsoft identity platform, lures the victim to the legitimate microsoft.com/devicelogin page to enter it, and a backend function (checkStatus()) polls every 3-5 seconds until the victim authenticates, handing the operator tokens without ever seeing a password. Delivery used 44 lure themes (invoices, RFPs, shared files, construction bids, compensation/benefits documents, password-expiration notices), multi-stage image links and redirect chains through compromised domains, fake CAPTCHA pages, automatic clipboard code copying, and hosting on Cloudflare Workers (workers.dev), Vercel (vercel.app), AWS Lambda and Bunny CDN. The kit supported token auto-refresh, Telegram keyword alerts on victim inboxes, and Microsoft Graph reconnaissance to map organizational structure.

The differentiator was an AI chatbot that read compromised mailboxes to identify vendor invoices, payment approvals and the people best placed to move money, with preset prompts for wire-transfer conversations and impersonation strategies; the platform also generated phishing emails with AI and was reportedly partially 'vibe coded'. Microsoft observed post-compromise email exfiltration, malicious inbox rules, new-device registration to obtain a Primary Refresh Token (within about 10 minutes in observed cases), deep reconnaissance of financial and executive accounts, and internal phishing relayed to trusted contacts. Targeted industries were wholesale distribution, construction, financial services, real estate, higher education and healthcare, concentrated in the US, Canada, UK, Australia, India and France.

On 2026-09-11 the UK Metropolitan Police cybercrime team arrested two men (aged 32 and 38; released on bail) on suspicion of making articles for use in fraud and money laundering. In September 2026 Microsoft and Health-ISAC, under authorization from the US District Court for the Eastern District of Virginia, seized 50 websites and disabled 150+ additional domains, working with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs (which mapped crypto flows toward downstream cash-out points). It was Microsoft DCU's 40th court-authorized disruption and its first against an end-to-end AI-enabled cybercrime service.

The TRM Labs article (2026-10-02) places this in a wider AI-crime context: FBI IC3 reported 22,364 AI-related complaints and nearly USD 893M in AI-tied losses in 2025 (of nearly USD 21B total reported losses); 2026 deepfake scam losses were reported as already exceeding 2025 by 263%; and an AI-generated YouTube scheme between February and August 2026 took 274.60 ETH from 224 victims by walking them through building a 'crypto trading bot' that was in fact a drainer contract they deployed themselves. The article cites Deepfake-Eval-2024, in which detector accuracy fell to 50% (video), 48% (audio) and 45% (images) versus academic benchmarks, and TRM's AI Crime Adoption Index rising from 28 (2024) to 54 (2026), with scams and fraud the only 'Mature' category. No CVEs, hashes, IP addresses or wallet addresses are published in the sources.

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1204.001 User Execution: Malicious Link
- T1528 Steal Application Access Token
- T1550.001 Use Alternate Authentication Material: Application Access Token
- T1098.005 Account Manipulation: Device Registration
- T1564.008 Hide Artifacts: Email Hiding Rules
- T1087.004 Account Discovery: Cloud Account
- T1114.002 Email Collection: Remote Email Collection
- T1534 Internal Spearphishing
- T1583.006 Acquire Infrastructure: Web Services
- T1684.001 Impersonation
- T1657 Financial Theft

## Sources

- [How Law Enforcement Uses AI to Fight AI-Enabled Crime](https://www.trmlabs.com/resources/blog/how-law-enforcement-uses-ai-to-fight-ai-enabled-crime)
- [Unmasking EvilTokens: Getting to the root of device code phishing](https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/)
- [Disrupting EvilTokens: The AI Chatbot Built for Cybercrime](https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/)
- [TRM Labs Supports Microsoft's Disruption of EvilTokens, an AI-Powered Cybercrime Service](https://www.trmlabs.com/resources/blog/trm-labs-supports-microsofts-disruption-of-eviltokens-an-ai-powered-cybercrime-service)
- [Two arrested in UK after Microsoft takedown of 'Eviltokens' AI-chatbot for cybercriminals](https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens)
- [Microsoft, partners disrupt EvilTokens, AI-powered phishing service](https://www.axios.com/2026/09/22/microsoft-eviltokens-court-takedown)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2873
