|
||

Microsoft has disrupted EvilTokens, a subscription cybercrime platform that combined account compromise with artificial intelligence to analyze stolen email, identify fraud opportunities and help attackers impersonate trusted contacts. Microsoft says the service was linked to more than 12,000 compromised inboxes at over 10,000 organizations within months of its launch in February.
The operation removed a substantial part of EvilTokens’ Internet infrastructure. Microsoft said it seized 50 websites used to operate the service and disabled more than 150 additional domains supporting it. The action was authorized by the U.S. District Court for the Eastern District of Virginia and coordinated with Health-ISAC and companies and organizations including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs.
The disruption was accompanied by arrests in Britain. According to Microsoft, Metropolitan Police cybercrime officers arrested two men, aged 32 and 38, on September 11 on suspicion of offenses connected with the alleged operation of EvilTokens. Both were subsequently released on conditional police bail while the investigation continues.
EvilTokens went beyond using AI to produce phishing messages. After attackers obtained access to an email account, the platform could analyze its contents to identify payment processes, financial conversations, organizational roles and trusted relationships. Microsoft said its tools could locate vendor invoices and wire-transfer discussions, identify employees able to move money and recommend people for attackers to impersonate.
That automation compressed work traditionally associated with business email compromise into a packaged service. EvilTokens was marketed through Telegram for a $1,500 initiation fee and a recurring $500 subscription, combining account compromise, mailbox analysis, target selection and preparation for financial fraud. Cisco Talos, which independently investigated EvilTokens-related infrastructure, documented an operator panel supporting device-code phishing, persistent account access, email compromise and data exfiltration.
The initial compromise exploited device-code authentication rather than stealing passwords directly. Victims were induced to enter an authentication code on Microsoft’s legitimate sign-in page, completing an authentication process that gave attackers access to their accounts. Microsoft warned that access could survive a password change unless associated sessions and tokens were also revoked.
Microsoft described the action as its first disruption of an end-to-end AI-enabled cybercrime service. It said victim activity was concentrated in the United States, Canada, Britain, Australia, India and France, across sectors including financial services, healthcare, higher education, real estate and construction. The case shows how AI-enabled cybercrime services can automate not only the creation of fraudulent content but the analysis of compromised organizations and selection of potentially valuable targets.
Sponsored byCSC
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byVerisign
Sponsored byVerisign
Sponsored byRadix
Sponsored byDNIB.com