ChannelLife Australia - Industry insider news for technology resellers
Australia
Cloudflare & Microsoft disrupt EvilTokens phishing service

Cloudflare & Microsoft disrupt EvilTokens phishing service

Wed, 23rd Sep 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Cloudflare and Microsoft have disrupted the EvilTokens phishing service, targeting a platform linked to more than 12,000 compromised inboxes across more than 10,000 organisations worldwide.

Australia was among the countries with the highest concentration of victim activity, according to Cloudflare's threat intelligence team, Cloudforce One. EvilTokens had become one of the more widely used phishing kits for bypassing multi-factor authentication in Microsoft Office 365 environments and launching business email compromise attacks.

EvilTokens emerged on Telegram and sold access to a web-based panel that automated the theft of authentication tokens. Those tokens let attackers retain access to email accounts even after session tokens expired, making it easier to keep monitoring inboxes and impersonating staff in financial or procurement conversations.

The service also included an AI coach that guided users in drafting phishing lures tied to US tax documents, invoices and accounting correspondence. The feature points to a shift in how criminal operators package tools and advice together for less experienced users seeking to run scams at scale.

Joint action

The disruption combined legal and technical measures. Microsoft's Digital Crimes Unit pursued a civil action in the United States to seek control of domains used in the attacks, while Cloudflare swept infrastructure linked to the service.

Cloudflare identified the full set of domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens customers. It then banned hundreds of domains and Worker projects, suspended accounts, and developed methods to detect and prevent deployment of the scripts used by the kit.

For domains that could not be seized because they were registered in jurisdictions that did not cooperate, warning pages were deployed to block victims from reaching the phishing content. That was intended to neutralise the kit even where the underlying domain remained online.

EvilTokens abused Cloudflare's infrastructure by using domains and Cloudflare Workers to host malicious logic. The platform let users bring their own Cloudflare API key, which could then be used to configure a Worker to collect credentials and set up phishing pages, with stolen details also routed to Telegram channels.

Professional setup

Investigators described EvilTokens as a professionalised criminal service. Victims received a range of phishing templates containing links and attachments, while the developers behind the service worked to obscure their scripts and tools to avoid detection.

The domains were purchased and set up by a third party based in another country, according to the investigation. Cloudflare said the same third party also configured domains for a competing phishing service and other scams, suggesting a broader support network behind the operation.

Business email compromise remains one of the most financially damaging forms of cybercrime because it often targets routine payments, invoices and supplier relationships rather than relying on malware alone. Access to a genuine corporate mailbox can help attackers send convincing messages within existing email threads, increasing the chance that staff approve fraudulent transfers or disclose sensitive information.

The use of token theft also highlights a weakness in some forms of multi-factor authentication. If an attacker can steal a valid session token after a user has authenticated, they may be able to bypass the extra login step without needing the second factor again.

Defence measures

Cloudflare said organisations should consider phishing-resistant authentication methods such as FIDO2, WebAuthn, hardware security keys and passkeys. It also recommended tighter conditional access controls, including restricting logins to managed devices, monitoring impossible travel patterns and limiting access from regions outside a company's operating footprint.

Other measures included shorter session lifetimes, continuous session evaluation, DNS filtering for newly registered domains, stronger email inspection, and stricter DMARC, SPF and DKIM policies. Cloudflare also listed several internal detections it uses to identify EvilTokens-linked campaigns at the point of email delivery.

Cloudflare said the disruption effort involved sharing indicators of compromise with national computer emergency response teams, government agencies and industry partners. It also published a sample of recent domains linked to the EvilTokens operation, alongside a SHA256 hash associated with the threat.

"Cloudflare, in partnership with Microsoft, has taken action against EvilTokens, a PhaaS platform designed to bypass MFA," Cloudflare said.