EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid
Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

Key points
- Microsoft's Digital Crimes Unit has disrupted EvilTokens, a phishing service that appeared in February 2026 and broke into more than 12,000 mailboxes across over 10,000 organisations before takedown.
- The kit sells for $1,500 up front plus $500 a month on Telegram, run by a group Microsoft tracks as Storm-2992.
- It abuses device code sign-in, the login flow made for smart TVs and conference phones, to slip past most multi-factor authentication.
- Victim organisations sit mainly in the United States, Canada, the United Kingdom, Australia and India, across construction, finance, real estate, healthcare and higher education.
- Microsoft recommends blocking device code sign-in entirely where it is not needed.
A phishing service called EvilTokens spent most of this year quietly hijacking corporate email accounts by abusing a login method most people have never heard of: the one your smart TV uses to sign in to Netflix.
Microsoft's Digital Crimes Unit says it has now dismantled the infrastructure behind the service. In a writeup from the Microsoft Security Response Center, the company says EvilTokens broke into more than 12,000 mailboxes across more than 10,000 organisations after surfacing in February 2026.
The honest read: this is what happens when defenders finally push everyone onto multi-factor authentication and criminals go looking for the login door that MFA doesn't really guard.
What is EvilTokens actually doing?
It's a phishing-as-a-service kit, meaning criminals rent it like software rather than build their own. Microsoft says it's sold on Telegram by a group it calls Storm-2992 for $1,500 to buy in and $500 a month to keep using the control panel.
Subscribers get ready-made fake login pages, 44 lure themes (invoices, shared files, requests for proposals), and an AI helper that reads a victim's inbox after break-in and drafts the next phishing email in the same tone. There's also a Telegram store bot for bolt-ons like a spam filter dodger and an SMTP sender for blasting the lures out.
How does the smart-TV login trick work?
Microsoft calls it device code phishing. It abuses a Microsoft feature called the device authorization grant, which is the sign-in flow for gadgets with no proper keyboard: smart TVs, printers, Teams room devices.
Normally the gadget shows you a short code, you type it into a browser on your phone or laptop, and the sign-in completes. The attacker inserts themselves at the start: they ask Microsoft for a code, then email it to you dressed up as something you were expecting, a Teams join or a document approval. Enter the code on the real Microsoft page and you've just handed the attacker's session a working token for your account.
Because you did the actual sign-in on the real site, MFA passes. The attacker never sees your password, only the access token, which is the digital pass that proves you're logged in. We've tracked this attack class since 19 June 2026, and as GhostCode showed on 18 September, a stolen token can survive a password reset entirely.
What do they do once inside?
Email theft, then quiet persistence. Microsoft says operators use the stolen tokens to read mail, set up hidden inbox rules that bury replies from finance or IT, and in some cases register a new device on the account so they still have access after the token expires. They also query Microsoft Graph, the interface that exposes an organisation's users and permissions, to map who is worth impersonating next.
That's the setup for business email compromise, where criminals hijack a real employee's mailbox to redirect an invoice payment or start a wire fraud from a trusted address.
The facts at a glance
| Item | Detail |
|---|---|
| Service name | EvilTokens |
| Operator | Storm-2992 (Microsoft tracking name) |
| Active since | February 2026 |
| Mailboxes hit | More than 12,000 |
| Organisations hit | More than 10,000 |
| Price | $1,500 upfront, $500/month |
Should you worry?
Any email that gives you a short code and tells you to type it into a Microsoft login page to "join", "approve" or "verify" something is the tell. A real Teams meeting or document share won't ask you to punch a code into microsoft.com/devicelogin.
For IT teams, Microsoft's guidance is blunt: block device code sign-in with a Conditional Access policy and carve out only the specific Teams room accounts that genuinely need it. MFA alone won't save you here. It never did against this one.



