EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Summary
Microsoft's Digital Crimes Unit (DCU) has disrupted the EvilTokens platform, which was used to compromise over 12,000 Microsoft accounts across more than 10,000 organizations. This platform enabled phishing-as-a-service (PhaaS) attacks.
IFF Assessment
FOE
The disruption of a phishing-as-a-service platform represents a win for defenders, but the fact that it successfully compromised thousands of accounts highlights an ongoing threat.
Defender Context
The disruption of EvilTokens highlights the persistent threat of phishing-as-a-service operations. Defenders should remain vigilant against sophisticated phishing campaigns, ensure robust multi-factor authentication is deployed, and train users to identify and report suspicious activity.