← Back to feed
PhishingEmerging1 sourceSep 23, 2026 · 10:59via Cyber Security News

The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine

Brief

EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password.

The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in.

The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise.

Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide.

Affected sectors include finance, construction, healthcare and education.

Read more on Cyber Security News