Microsoft Disrupts EvilTokens Phishing-as-a-Service, Seizes 50 Sites and 150 Domains

Moyen · Dark Reading ·

En bref

  • Microsoft acted against the operators of EvilTokens, a phishing-as-a-service platform.
  • The disruption included seizure of 50 websites and disabling of 150 domains.
  • No CVE is linked to the event; the impact is service disruption for the operation.
  • Microsoft 365 users should review phishing and identity defenses.

Microsoft launched a synchronized operation targeting the individuals behind EvilTokens, a phishing-as-a-service offering aimed at Microsoft 365. The operation resulted in service disruption for the group behind the service. As part of the enforcement, 50 websites were seized and 150 domains were disabled.

The scale of the takedown is notable: dozens of web properties and well over a hundred domains tied to the service were removed from operation. This kind of coordinated disruption can slow phishing campaigns, but it does not eliminate the broader threat. Operators may rebuild or shift to other infrastructure.

EvilTokens is described as phishing-as-a-service, a model that lets less skilled attackers rent or reuse phishing tools. Microsoft 365 is the named product in this context, making identity protection a priority for organizations that rely on the suite. Schools, agencies, and businesses should assume that phishing attempts against cloud accounts will continue.

No CVE is associated with this event, so there is no vulnerability patch to apply. The impact is service disruption for the phishing operation, not a confirmed breach of Microsoft 365 tenants. The severity is medium.

For K-12 IT teams, the practical response is to strengthen account defenses and watch for related activity. Review sign-in logs, block known malicious domains, and remind staff to report suspicious messages. Monitor for new domains or campaigns that may emerge after the takedown.

À faire maintenant

  1. Enforce phishing-resistant MFA for all Microsoft 365 accounts, prioritizing administrators and high-risk users.
  2. Review and tighten Conditional Access policies to block legacy authentication and suspicious sign-ins.
  3. Add known EvilTokens domains and related indicators to email, DNS, and web proxy blocklists.
  4. Audit Microsoft 365 sign-in logs, mailbox forwarding rules, and OAuth application consents for anomalies.
  5. Send a targeted phishing awareness reminder and make sure users can report suspicious messages easily.
  6. Coordinate with Microsoft and sector threat-sharing groups for updated indicators and takedown follow-up.
  7. Test account recovery and incident response procedures in case a credential phishing attempt succeeds.

Source originale

Dark Reading

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber