decrypted · 23 september 2026 · ransomware and cybercrime · supply chain · ai and llm security

EvilTokens is down, but the device login door is still open

Microsoft said on Tuesday that it has broken up EvilTokens, a phishing service that used artificial intelligence to help criminals rob businesses through their own Microsoft 365 inboxes, and the Metropolitan Police have arrested two men, aged 32 and 38, on suspicion of making articles for use in fraud and of money laundering. It is also a reminder that a takedown removes the shop, not the door the shop was using.

How the trick works

EvilTokens abused the device code flow, a login method designed for televisions, printers and meeting-room hardware that have no keyboard. The device asks Microsoft for a short code, and a person finishes the sign-in on their own phone or laptop by typing that code at microsoft.com/devicelogin. The criminals started the request themselves, then sent victims a lure that led to Microsoft's genuine login page and asked them to enter the code.

Think of it as being asked to sign a visitor in at a real reception desk. The desk is real, the receptionist is friendly, and you are the one who has just vouched for a stranger. Microsoft's analysis describes a script polling the attacker's server every three to five seconds, and the moment the victim completes the step, the attacker's session is authorised.

The AI part, and the numbers

The service launched in February 2026 and, according to Microsoft, was linked to more than 12,000 compromised inboxes across more than 10,000 organisations, with victims concentrated in the United States, Canada, the UK, Australia, India and France. It sold 44 phishing themes for $1,500 up front and $500 a month. Its chatbot, Microsoft says, could analyse a stolen inbox to find trusted relationships, payment approvals and the people who handle money, so the follow-up fraud arrived already tailored.

Microsoft's Digital Crimes Unit seized 50 websites and disabled more than 150 further domains, with court authorisation from a US federal court in Virginia. The arrests came earlier this month.

What the defender sees

Very little. The sign-in happens on Microsoft's real page, so there is no fake domain to blocklist and no password to steal. Microsoft's advice for the fraud end is to verify any request to change payment details or redirect funds through a second trusted channel, and to assume a compromised inbox can be mined in minutes rather than days.

The Secure by Design lesson

A login path built for keyboardless gadgets sits open for organisations that will never use it. Secure by Design says a capability nobody needs should not be reachable, and a risky one should be denied by default and allowed by exception. Microsoft's own guidance is to block device code flow wherever possible with Conditional Access, scoping any exceptions to specific Teams device resource accounts, and to move staff towards phishing-resistant sign-in such as FIDO2 keys.

The cost is modest: one policy, a look at who genuinely uses the flow, and a short exception list. It is the sort of job that slips down the list until an incident promotes it. A call-back rule for bank detail changes costs finance a few minutes a week and blunts the fraud that follows. The service is gone; the flow it abused is not. Ask your IT lead this week whether it is still open. Opinion, not advice.

Also this week

Arista VeloCloud Orchestrator (vulnerability). Arista has patched CVE-2026-93952 in on-premises VeloCloud Orchestrator, which it says is actively exploited. According to BleepingComputer and SecurityWeek, improper input validation in certificate-based authentication lets a remote attacker reach privileged internal functions without credentials, and hosted instances were already patched. CISA added it to its exploited list on 22 September. Sources differ on the severity score, so I have left it out. The lesson is old: a management console should not face the internet, and Arista itself says limiting web access reduces exposure. If a supplier runs it for you, ask whether it is the on-premises version.

ClosedQuorum (AI security). Cisco Talos has documented a Windows implant that asks four commercial AI models, DeepSeek, Qwen, Mistral and Gemini, to vote on its next action instead of calling a command server. Talos calls it the first publicly documented Windows implant to hand command decisions to AI models. Talos has not confirmed use in the wild: the public build carries placeholder keys, and its lateral movement option has no code behind it. Talos suggests watching for endpoints that talk to AI services alongside credential-store access and process injection. A workstation with no business calling an AI provider is a cheap thing to block.

BigCommerce and Ribon (supply chain). Attackers used a compromised BigCommerce application key held by Ribon, a shopping app, to pull shopper names, emails, phone numbers and postal addresses between 13 and 17 September. Card data and passwords were not exposed, and BigCommerce says its own platform was not breached. Master of Malt, a UK retailer, confirmed it was affected and said Ribon was installed on hundreds of stores. Merchants, not app vendors, will be the ones explaining this to customers. Treat every installed app as a supplier, and give its key the narrowest scope it can work with.

Sources

Not sure which sign-in paths your own tenant leaves open? get in touch and we will take a look.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.