Executive Summary
Recent investigations by Eye Security have identified two sophisticated Phishing-as-a-Service (PhaaS) kits, dubbed TokenLover and YaksaLover, which are currently being leveraged in Business Email Compromise (BEC) campaigns. Attributed to the actor Storm-2372, these kits facilitate industrial-scale compromise of Microsoft 365 environments by automating the theft of tokens and the bypass of multi-factor authentication (MFA).
The attack chain typically begins with device code phishing, which yields a Primary Refresh Token (PRT). The kits then utilize FOCI pivoting to gain access to all Microsoft services and, critically, register synthetic Windows Hello for Business (NGC) keys to ensure persistence that survives password resets. TokenLover specifically incorporates an AI pipeline to analyze mailbox contents for financial intelligence, such as outstanding invoices and payment approval flows, to facilitate fraudulent wire transfers.
These kits represent a significant evolution in BEC tradecraft by lowering the barrier to entry for low-skilled operators while increasing the speed and scale of post-exploitation activities. Organizations should prioritize monitoring for anomalous Entra ID device registrations and the registration of new NGC keys.
