AI-Powered Phishing-as-a-Service Kits Target Microsoft 365 Identities
Score: 8/10

AI-Powered Phishing-as-a-Service Kits Target Microsoft 365 Identities

The threat actor Storm-2372 is utilizing AI-built phishing kits, TokenLover and YaksaLover, to automate large-scale BEC attacks and persistence via Windows Hello for Business key injection.

Executive Summary

Recent investigations by Eye Security have identified two sophisticated Phishing-as-a-Service (PhaaS) kits, dubbed TokenLover and YaksaLover, which are currently being leveraged in Business Email Compromise (BEC) campaigns. Attributed to the actor Storm-2372, these kits facilitate industrial-scale compromise of Microsoft 365 environments by automating the theft of tokens and the bypass of multi-factor authentication (MFA).

The attack chain typically begins with device code phishing, which yields a Primary Refresh Token (PRT). The kits then utilize FOCI pivoting to gain access to all Microsoft services and, critically, register synthetic Windows Hello for Business (NGC) keys to ensure persistence that survives password resets. TokenLover specifically incorporates an AI pipeline to analyze mailbox contents for financial intelligence, such as outstanding invoices and payment approval flows, to facilitate fraudulent wire transfers.

These kits represent a significant evolution in BEC tradecraft by lowering the barrier to entry for low-skilled operators while increasing the speed and scale of post-exploitation activities. Organizations should prioritize monitoring for anomalous Entra ID device registrations and the registration of new NGC keys.

Key Details

Threat Name

TokenLover and YaksaLover Phishing Kits

Affects

WordPress core, Time4Popcorn, PopcornTime

Adversary

Storm-2372

Malware/Tools

TokenLover, YaksaLover, GraphRunner

Report Score

8out of 10
Quality Score
Good
IOC Quality4
TTP Details9
Detection Guidance6
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources