Cloudflare and Microsoft Disrupt EvilTokens Phishing-as-a-Service Operation
Cybercrime Platform Targeted Microsoft 365 Accounts and Authentication Tokens
Cloudflare’s threat intelligence unit, Cloudforce One, has taken part in an international effort led by Microsoft and supported by law enforcement and industry partners to disrupt EvilTokens, a phishing-as-a-service operation targeting Microsoft 365 users.
The operation focused on infrastructure used to steal authentication information and support Business Email Compromise (BEC) activity. According to Cloudflare, the coordinated effort brought together legal measures and technical disruption to make the cybercrime service harder to operate.
Microsoft’s Digital Crimes Unit (DCU) pursued civil legal action involving domains connected with EvilTokens. Cloudforce One, meanwhile, investigated and disrupted malicious infrastructure operating through Cloudflare’s network, including hundreds of domains and malicious Cloudflare Worker projects.
EvilTokens Offered Automated Tools for Cybercriminals
EvilTokens appeared on Telegram in January 2026 and offered customers access to an online panel designed to automate the theft of authentication tokens associated with Microsoft Office 365 environments.
Unlike traditional credential-focused phishing campaigns, the platform was built around obtaining authenticated sessions and tokens. This approach could allow attackers to continue accessing compromised accounts and use those accounts in later stages of an attack.
The service also featured an AI-based coaching component. Cloudflare said the system provided guidance related to areas such as Business Email Compromise, U.S. tax documentation and common invoice and accounting communications.
Such capabilities could help attackers create more convincing phishing messages and impersonation scenarios without requiring extensive technical experience.
Cloudflare Workers Used as Part of the Infrastructure
Cloudflare’s investigation identified the use of Cloudflare API keys within the EvilTokens platform.
According to the company, users of the service could submit their own API credentials through the criminal panel. Those credentials were then used to configure Cloudflare Workers associated with phishing activity and credential collection.
Information stolen through the campaigns could subsequently be sent to attackers through Telegram.
The case illustrates how cybercrime services are increasingly packaging infrastructure, automation and operational guidance into ready-to-use platforms that can be accessed by multiple criminal customers.
Implications for Organisations in the Middle East and Africa
Although EvilTokens operated internationally, the techniques involved have particular relevance for organisations across the Middle East and Africa.
Microsoft 365 and other cloud collaboration services are widely used by organisations across sectors including government, financial services, healthcare, education and professional services.
A compromised business email account can expose more than login credentials. Attackers may gain access to legitimate conversations, contacts, invoices and other business information that can be used to make fraudulent communications appear authentic.
The use of authentication tokens adds another layer to the threat because attackers can attempt to take advantage of an already authenticated session rather than relying solely on obtaining a username and password.
Coordinated Action Disrupts EvilTokens Infrastructure
The disruption operation took place on September 15, when Cloudforce One worked with Microsoft and other partners to target infrastructure associated with EvilTokens.
Microsoft investigated domains connected to attacks against its customers and shared relevant intelligence with strategic partners, including Cloudflare.
Cloudforce One then used its threat intelligence capabilities and visibility across its network to identify additional infrastructure linked to the operation.
Cloudflare said it subsequently removed malicious Workers projects, blocked hundreds of domains and suspended accounts associated with the activity. The company also developed detections intended to prevent malicious Worker scripts from being redeployed.
In jurisdictions where domains could not be taken over through legal proceedings, Cloudflare used warning pages to help prevent users from accessing the identified phishing infrastructure.
Organisations Urged to Strengthen Authentication and Email Security
The EvilTokens operation also highlights the changing nature of phishing attacks. While MFA remains an important security control, organisations increasingly need additional safeguards around authenticated sessions and identity infrastructure.
Cloudflare recommends the use of phishing-resistant authentication technologies such as FIDO2, WebAuthn, hardware security keys and passkeys. Strong conditional-access policies can provide another layer of protection.
Organisations can also monitor session activity and implement appropriate session-management controls. Email and DNS security technologies can help identify suspicious links, attachments and infrastructure associated with phishing campaigns.
Cloudflare further recommends properly configuring DMARC, SPF and DKIM to strengthen email authentication and reduce opportunities for impersonation.
“For organisations across the Middle East and Africa, the incident provides a broader reminder that cybercriminals are adopting the same automation and AI technologies that businesses use to improve productivity, but applying them to scale fraud and credential theft. As phishing-as-a-service continues to lower the technical barrier for attackers, collaboration between cloud providers, security teams, threat intelligence organisations, technology companies and law enforcement will be increasingly important to identify and disrupt criminal infrastructure before it can cause further harm,” said Ercan Aydin, AVP, Middle East, Turkey & Africa at Cloudflare.


