TECH NEWS | Cloudflare, Microsoft disrupt EvilTokens phishing service

0

EvilTokens began operating on Telegram in January 2026, offering access to a web-based panel that automated the collection of authentication tokens for Microsoft Office 365 environments.

eveiltokens

Cloudflare and Microsoft have disrupted EvilTokens, a Phishing-as-a-Service operation that automated the theft of authentication tokens and was used in Business Email Compromise campaigns, the companies said.

Cloudflare’s Cloudforce One threat research team worked with Microsoft and other industry and law enforcement partners in the operation, which targeted EvilTokens infrastructure on Sept. 15, 2026. Cloudflare said the service had harmed thousands of users globally and caused significant financial losses.

EvilTokens began operating on Telegram in January 2026, offering access to a web-based panel that automated the collection of authentication tokens for Microsoft Office 365 environments.

According to Cloudflare, the service also enabled persistent access after a session token expired, allowing its users to circumvent multifactor authentication protections.

The panel included an AI coach that provided guidance on subjects including U.S. tax documents, Business Email Compromise and typical invoice and accounting correspondence. Cloudflare said the feature lowered the technical expertise required to create phishing campaigns.

EvilTokens users could provide their own Cloudflare API keys to configure Cloudflare Workers used to collect credentials and set up phishing pages. The credentials could also be sent to users through Telegram channels.

Coordinated disruption

Cloudforce One joined Microsoft in a coordinated legal and technical operation on Sept. 15 to dismantle the infrastructure supporting EvilTokens.

Microsoft initiated the investigation by identifying domains used in attacks against its customers and shared its findings with strategic partners, including Cloudflare. Cloudflare said its analysis identified the broader domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens customers.

Microsoft filed a civil action in a U.S. court seeking to suspend malicious domains and transfer control of them to its Digital Crimes Unit. Cloudflare separately banned hundreds of domains and Workers projects associated with the operation and developed detection methods to prevent malicious Workers scripts from being deployed.

For domains whose registrars were located in jurisdictions where legal seizure was not possible, Cloudflare said it deployed warning pages designed to block victims from accessing EvilTokens phishing links.

Cloudflare said the operation also involved coordination with a law enforcement agency, although details of that action will be disclosed in the future.

Defending against phishing services

Cloudflare recommended phishing-resistant multifactor authentication, including FIDO2/WebAuthn and passkeys, along with certificate-based authentication.

It also recommended conditional access controls, stronger session protections and network and email defenses such as DNS filtering, email security, sandboxing, and strict DMARC, SPF and DKIM policies.

Cloudflare said its email security systems use detection fingerprints and machine learning models to identify malicious messages based on domain reputation, content, sentiment and metadata.

The company also provides a free Retro Scan tool that allows organizations, including non-Cloudflare customers, to scan existing inbox messages for threats, according to the report.

Cloudflare said EvilTokens was among the more popular phishing kits used by criminals to gain access to inboxes and launch Business Email Compromise campaigns. The company described the disruption as part of a broader effort to dismantle Phishing-as-a-Service infrastructure.


Full disclosure: All news articles published on the TechSabado website are written by human journalists, unless otherwise specified. Final text editing is also performed by human editors, with artificial intelligence (AI) used only to assist with additional grammar and style guide corrections..


————————————————————————-
TEN YEARS OF TECHSABADO!


PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE & SPOTIFY channels.



WATCH TECHSABADO ON OUR YOUTUBE CHANNEL:



























WE ARE ALSO ON SPOTIFY



WATCH OUR OTHER YOUTUBE CHANNELS:




PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE CHANNEL.






















WE ARE ALSO ON SPOTIFY



WATCH OUR OTHER YOUTUBE CHANNELS:




PLEASE LIKE our FACEBOOK PAGE and SUBSCRIBE to OUR YOUTUBE CHANNEL.

roborter
by TechSabado.com editors
Tech News Website at  | Website

Leave a Reply

Your email address will not be published. Required fields are marked *