Weekly Phishing Roundup: EvilTokens Taken Down, Revolut Texts, Fake Bitrefill Checkouts
Our weekly roundup of phishing and scam campaigns worth knowing about, with what to look for in each one. This week there's good news for once: one of the phishing services we wrote about in July has been shut down.
1. Microsoft takes down EvilTokens
On 22 September Microsoft's Digital Crimes Unit said it had dismantled EvilTokens, a phishing-as-a-service platform it tracks as Storm-2992. The service was linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organisations, including victims in the US, UK, Canada, France, Australia and India. With a US court order, Microsoft and its partners seized 50 websites and disabled more than 150 other domains. London's Metropolitan Police arrested two men, aged 32 and 38, on 11 September. Both have been released on bail while the investigation continues.
EvilTokens abused Microsoft's device-code sign-in. The victim is shown a code and sent to the real microsoft.com/devicelogin page to enter it, which signs the attacker's session in. The service charged $1,500 up front plus $500 a month, and Coinbase traced about $1.1 million in payments to it. We covered how its pages hide from scanners in Ghost Phishing: why a clean URL scan no longer means a clean page.
What to look for: nobody legitimate emails you a code and asks you to type it in at devicelogin. If you didn't start a sign-in on a TV or another device yourself, don't enter the code.
2. Revolut phishing texts, two days after a breach
Revolut confirmed that attackers got customer records by sending requests that appeared to come from a government agency. The data included dates of birth, addresses, email addresses, phone numbers, ID documents, selfies and transaction history. Malwarebytes reported phishing texts two days later. Some appeared inside existing Revolut message threads, and they led to a page that asked for camera access, faked Revolut's "turn your head" identity check, and then asked for the password.
What to look for: a text sitting in your bank's usual thread proves nothing, because sender names can be spoofed. Open the bank's app yourself instead of following the link.
3. Fake Bitrefill checkouts in search results
Bitrefill says copies of its checkout page, on similar-looking names, are showing up in search results. Malwarebytes documented the tricks: swapped letters (biterflll), extra words like "pay" or "gift", and internationalised domains that display as "Bitrefill" but are really xn-- Punycode addresses. Victims send cryptocurrency, which can't be reversed.
What to look for: for anything involving payment, use a bookmark rather than a search result, and check the domain letter by letter before approving.
4. Zoom and DocuSign emails, the old-fashioned way
Kaspersky reported a two-wave campaign: fake DocuSign emails first, then Zoom "your account will be disabled" notices a little over a week later. By 11 September it had seen more than 1,000 of these emails. Some linked to credential-stealing pages, while others put a form in the email itself asking for personal and card details. Kaspersky's point was that simple tricks still work when people are wading through a busy inbox.
What to look for: account-closure threats are a pressure tactic. Sign in to Zoom or DocuSign directly and check whether anything is actually wrong.
5. Fake antivirus renewal pages, now written by AI
Malwarebytes found a fake Avast "cancel your renewal" page, aimed at Belgium, that showed signs of being generated by AI. It doesn't ask for a password. It only asks for your name, email address and phone number, and that tells the scammers you're likely to answer when they call about the "payment".
What to look for: check subscriptions in your bank app or the vendor's own site. A page whose main question is your phone number is setting up a phone call, and tech-support scams usually come next.
The pattern this week
Four of these five campaigns send you to a page on a domain that isn't the real one. The fifth, EvilTokens, uses the real Microsoft page but starts from a lure page that isn't. Checking the domain before you type anything is still the most useful habit you can have, and it's the check PhishClean runs on every page for you: lookalike and Punycode domains, forms that send data to another site, and pages that copy a brand they aren't.
Sources
- The Hacker News: Microsoft takes down EvilTokens device-code phishing service tied to 12,000 inbox compromises
- Malwarebytes: Revolut phishing texts appear days after data breach
- Malwarebytes: Search results are sending people to fake Bitrefill checkouts
- Our Daily News: Zoom and DocuSign phishing scam (Kaspersky)
- Malwarebytes: AI helps scammers build convincing antivirus renewal pages
Let the domain check run itself
PhishClean checks every page for lookalike and Punycode domains, brand copies and forms that post to another site.
Install PhishClean FreeLast updated: