Cloudflare participates in global operation to disrupt EvilTokens Phishing-as-a-Service

Threat brief - Sep 22, 2026

Overview

Cloudflare’s Cloudforce One threat research team worked with Microsoft and other industry and law enforcement partners to disrupt the EvilTokens Phishing-as-a-Service crime organization. EvilTokens sold access to a web based panel that gave criminal customers an automated system for collecting tokens used for authentication to Microsoft Office 365 environments. EvilTokens and their customers harmed thousands of users around the world and caused significant financial losses to victims of Business Email Compromise. EvilTokens abused Cloudflare’s infrastructure by configuring domains and Cloudflare Workers that helped them facilitate the harm to Microsoft and Cloudflare customers.

Executive summary

  • Cloudflare, in partnership with Microsoft, has taken action against EvilTokens, a PhaaS platform designed to bypass MFA. It was one of the most popular kits used by criminals who exploit access to inboxes and launch Business Email Compromise campaigns.

  • The kits abused Cloudflare Workers to host malicious logic.

  • In September 2026, in a coordinated effort to disrupt this cybercriminal ecosystem, Cloudflare executed a technical takedown of the Workers projects and infrastructure supporting the kit. This action was coordinated with a civil legal process initiated by Microsoft’s Digital Crimes Unit (DCU) to seize associated domains from registrars worldwide.

  • This report provides technical details of the actor's TTPs, our disruption strategy, and how others can protect themselves from similar threats.

What is EvilTokens?

EvilTokens began their operation on Telegram in January 2026 and offered users access to the crime service’s panel that automated the process of collecting the tokens and enabling persistent access after a session token has expired. The EvilTokens panel had an AI coach that guided criminals on topics like US tax documents, Business Email Compromise, and formats of typical invoice and accounting related correspondence. EvilTokens users could bring their own Cloudflare API key to the EvilTokens panel which would be used to configure a Cloudflare Worker that collected credentials and setup the phishing webpage. The credentials would also appear in the users’ Telegram channels.

Victims received a variety of templates including compelling links and attachments.

To try to maintain the longevity of their infrastructure, EvilTokens developers went to great lengths to obfuscate their scripts and tools to evade detection. EvilTokens used domains that were purchased and set up by a third party based in another country. The third party also configured domains for a competing Phishing-as-a-Service kit and other types of scams.

EvilTokens operated a professionalised service from a Telegram channel.

Disruption

On September 15, 2026, Cloudforce One joined Microsoft in a multi-partner operation designed to dismantle the EvilTokens infrastructure across both the legal and technical fronts. Microsoft initiated the process by identifying and analyzing domains specifically used in attacks against its global customer base.

Microsoft shared these findings with a network of strategic partners, including Cloudflare, to expand the scope of the investigation and synchronize a global disruption operation aimed at dismantling the EvilTokens infrastructure. Through extensive research and analysis of the infrastructure, Cloudflare was able to identify the complete list of domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens’ customers.

The operation proceeded through several concurrent but coordinated layers of enforcement:

  • Microsoft’s civil action: Microsoft filed a civil action in a U.S. court to legally compel international domain registrars to suspend malicious domains and transfer control to Microsoft’s Digital Crimes Unit. These seized domains will be redirected to a web page displaying a message about the disruption and all of the participating organizations’ logos.

  • Mass infrastructure purge: Cloudflare separately executed a comprehensive sweep to clear out all zones associated with the threat, resulting in the banning of hundreds of domains and Workers projects.

  • Killing Worker scripts and suspending accounts: Cloudflare developed reliable detection methods for the Workers scripts that have been configured to prevent deployment.

  • Law enforcement coordination: An enforcement action was conducted by a law enforcement agency. The specifics of the action will be made public in the future.

Because the registrars for some of these EvilTokens domains are located in non-cooperative jurisdictions, technical intervention remained a critical failsafe. For any infrastructure that could not be legally seized, Cloudflare deployed interstitial warning pages. This ensures that any victim attempting to access an EvilTokens phishing link is blocked by a high-visibility security alert, effectively neutralizing the phishing kit even if the underlying domain remains technically active on the internet.

Mitigation and detection

Effective defense against EvilTokens and similar PhaaS platforms requires email security solutions that rely on proactive identification of delivery infrastructure and advanced behavioral detection models. Cloudflare Email Security maintains this defensive posture through the use of Email Detection Fingerprints (EDF) alongside continuous refinement of specialized detection logic designed to adapt to the actor's shifting tactics. Tailored detections like those provided below identify and neutralize these campaigns at the ingestion point:

  • EvilTokens.Workers.Dev.S_Account.Phishing

  • Phishing_Kit.EvilTokens.DeviceCode.Link

  • EvilTokens.Known.Affiliate.Domains

  • EvilTokens.Voicemail.Lure.Device_Code

These detections evaluate domain reputation, alongside capabilities to identify suspicious sentiment and branding within the messages. We combine these high-confidence detections in our production environment along with proactive threat hunting techniques to identify emerging email-based threats. Additionally, these detections leverage our machine learning models, which analyze email content, sentiment and metadata to detect and flag malicious messages.

Recommendations

Cloudflare recommends the following steps to mitigate threats from Phishing-as-a-Service operations like EvilTokens.

Upgrade to phishing-resistant MFA

  • Adopt FIDO2/WebAuthn: Use hardware keys (YubiKeys) or Passkeys. They use a cryptographic handshake that fails if the URL is even slightly off.

  • Deploy Certificate-Based Auth (CBA): Restrict access to devices with unique, pre-installed digital certificates to ensure only trusted hardware can connect.

Implement strict conditional access

  • Require managed devices: Block any login attempt not coming from a corporate-enrolled device (via Intune/Jamf).

  • Enforce geofencing: Block traffic from high-risk regions or countries outside your operational footprint.

  • Flag impossible travel: Trigger immediate alerts for sessions that jump vast distances faster than a plane can fly.

Harden session integrity

  • Enable token binding: Lock session tokens to the specific TLS connection; stolen cookies become useless on an attacker's machine.

  • Shorten session lifespans: Force frequent re-authentication to shrink the "window of opportunity" for stolen tokens.

  • Use Continuous Access Evaluation (CAE): Kill active sessions instantly if a user's IP changes or risk levels spike.

Strengthen network & email defenses

  • DNS filtering: Automatically block "newly registered domains" to stop fresh phishing links in their tracks.

  • AI-driven email security: Use tools like Cloudflare to identify real-time infrastructure fingerprints used by platforms like EvilTokens.

  • Sandboxing & deep inspection: Detonate links in isolated environments to expose hidden redirects before they reach the user.

  • Strict DMARC/SPF/DKIM: Move to a "Reject" policy to prevent brand spoofing and unauthorized sender impersonation.

In addition, we provide all organizations (whether a Cloudflare customer or not) with free access to our email Retro Scan tool, allowing them to use our predictive AI models to scan existing inbox messages. Retro Scan will detect and highlight any threats found, enabling organizations to remediate them directly in their email accounts. With these insights, organizations can implement further controls, either using Cloudflare Email Security or their preferred solution, to prevent similar threats from reaching their inboxes in the future.


Indicators of compromise

The domains listed below represent a small snapshot of the more recent infrastructure associated with the EvilTokens criminal enterprise. The table constitutes only a fraction of the extensive indicators tracked by Cloudforce One. Cloudforce One customers can access the complete list of indicators and associated analytical context via the Threat Events platform. To support global mitigation efforts, the disruption operation involved disseminating the IOCs to participating national CERTs, government agencies, and strategic industry partners.

Domain
aelararetailnexus[.]com
alejandroyu[.]org
allnaturalwellness[.]org
almagestshop[.]org
ashforgemaplehold[.]com
aspentrekgoods[.]org
asteronllc[.]com
azuresunprotectionco[.]com
azuresunprotectionco[.]org
bayloramuse[.]com
bojuhomefurnishings[.]com
brylindorcove[.]com
campscapellc[.]com
casasbella[.]org
catchingthewindoutdoors[.]org
clevion[.]org
comforthavenyyds[.]com
cozyhavenbroccolillc[.]com
crepestitchseamhollow[.]com
crystalbrow[.]com
cynthiasports[.]com
extremeadventure[.]org
faelthornebrook[.]com
fashionablespaces[.]com
fashionfusiongreenllc[.]com
globespeakapp[.]com
glowpixelinnovations[.]com
hatchelnook[.]org
headwearhaven[.]com
homeofexcellentproducts[.]org
intimateeleganceintimates[.]com
ironpeaksupply[.]cc
jorventhread[.]com
joyfulworkshop[.]org
kaoqumini[.]com
kynlinhome[.]com
legendaryoutdoor[.]org
linorallc[.]org
logicnestaisolutions[.]org
lunverollc[.]com
markelasoft[.]com
marventhhold[.]com
mckenziesexy[.]com
mengchongbaotoys[.]com
monothreads[.]org
morgangentleman[.]com
muyiju[.]org
nestsort[.]net
netstrikebadminton[.]com
nevorohomellc[.]com
nexusintimategoods[.]com
noriquellc[.]com
norlume[.]org
norvelynthread[.]com
pawsprint[.]cc
pinkpawgo[.]org
plushseat[.]org
puredwelling[.]org
purelyelegant[.]org
ridgewellapparel[.]com
roamcase[.]org
roamload[.]com
scantechinnovations[.]com
serenthorneglen[.]com
silkhavenkaiellc[.]com
smartviewdevices[.]com
soarbox[.]net
spacetidyllc[.]com
stepbreeze[.]com
thalwicklifestyle[.]com
tinymarvels[.]org
toetales[.]net
trailcrownllc[.]com
velouraintimates[.]com
veyramarketcollective[.]com
wildwoodoutfitters[.]org
wordlinktranslator[.]com
wovendaily[.]org
xuenoerlingeriellc[.]net
yuntuoutdoorbackpack[.]cc

SHA256 Hash
7fb2089b649c929fc21861759c63f1fc09066b26cabe10685c2bca2a983587f8

Get updates from Cloudforce One

Related research

Cloudflare participates in global operation to disrupt RaccoonO365
Cloudflare participates in global operation to disrupt RaccoonO365

Threat report

Tycoon 2FA - Resource card image
Cloudflare participates in global operation to disrupt Tycoon 2FA

Threat report

Attackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloads
Attackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloads

Threat report