How Hackers Weaponised “Device Codes” & AI: Inside Microsoft’s EvilTokens Takeover

How Hackers Weaponised "Device Codes" & AI: Inside Microsoft’s EvilTokens Takeover

If you’ve ever had to log into a smart TV, a office printer, or Microsoft Teams on a conference room screen, you’re probably familiar with the device code flow. You turn on the screen, it gives you a short string of letters, and it tells you to go to a web address on your phone or laptop to type it in.

It’s quick, convenient, and feels safe because you’re authenticating on your own phone.

However, tech giants aren’t the only ones leveraging AI and smart automation. Microsoft’s Digital Crimes Unit, working alongside law enforcement—including the UK’s Metropolitan Police—has officially dismantled EvilTokens, a sophisticated “Phishing-as-a-Service” (PhaaS) platform. Before its infrastructure was seized, the service managed to compromise over 12,000 email inboxes across 10,000 organisations worldwide.

What Was EvilTokens and How Did It Work?

Operating like a dark-web SaaS platform via Telegram, EvilTokens charged hackers an initiation fee of $1,500 (plus $500 a month) for access to turnkey cybercrime tools.

Instead of traditional password-stealing pages, EvilTokens weaponised Microsoft’s legitimate OAuth 2.0 device code authentication:

  1. The AI Lure: Victims received highly convincing phishing emails—often disguised as invoice updates, shared file notifications, or eFax messages—crafted using generative AI.
  2. The Code Trap: Clicking the link directed users to a page displaying a code alongside a button redirecting them to Microsoft’s official [microsoft.com/devicelogin](https://microsoft.com/devicelogin) portal.
  3. The Bypass: Because victims entered the code on Microsoft’s actual site and completed their standard login (including Multi-Factor Authentication), they unwittingly granted the hackers full session access—completely bypassing traditional password checks and MFA alerts.

The AI Edge: Sifting Through Inboxes in Seconds

What set EvilTokens apart from older phishing kits was its heavy integration of artificial intelligence across the entire attack process.

Once a hacker gained access to a victim’s Microsoft account, EvilTokens deployed an AI-powered analyst tool. Instead of a human criminal spending days manually reading through thousands of old emails, the AI scanned the inbox in seconds to:

  • Map out organizational hierarchies and identify key decision-makers.
  • Flag active invoice threads and payment discussions.
  • Identify high-value targets for internal Business Email Compromise (BEC) scams.

By automating both the initial trickery and the post-breach reconnaissance, the platform allowed low-level cybercriminals to launch sophisticated enterprise attacks at scale.

What This Means for Small Businesses and Creators

While massive corporate hacks dominate the headlines, platforms like EvilTokens prove that the technical barrier for high-level cybercrime has drastically dropped. Cybercriminals no longer need advanced coding skills; they just need a subscription and an automated script.

For UK small businesses, freelancers, and content creators, the incident highlights a few crucial takeaways:

  • MFA Isn’t a Silver Bullet: While Multi-Factor Authentication remains essential, modern device-code and token-stealing attacks show that clicking links without verifying the context can still bypass security layers.
  • Be Wary of Device-Code Prompts: Unless you are actively setting up a smart TV, conference screen, or secondary app that you personally initiated, never enter a code into [microsoft.com/devicelogin](https://microsoft.com/devicelogin).
  • Revoke Sessions, Don’t Just Reset Passwords: If an account is ever suspected of being compromised, simply changing your password isn’t enough—hackers holding valid access tokens can retain entry. System admins must explicitly invalidate all active user sessions and tokens.

Microsoft has recommended that IT administrators restrict or completely block device-code login flows across their organisations wherever they aren’t strictly required. As AI tools lower the bar for sophisticated fraud, keeping an eye on human awareness remains just as critical as software patches.

Be the first to comment

Leave a Reply

Your email address will not be published.


*