THEMETASEC

Cybersecurity News, Aggregated

Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime

CSO Online · 26 minutes ago Breach

Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to those capabilities, with a $1,500 initial sign-up fee and $500 monthly subscription, marketed through Telegram channels. “EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,” Microsoft explains in a post about the takedown. “Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.” The cybercrime platform abusing Microsoft’s OAuth 2.0 device-code authentication flow to steal valid session tokens through device code phishing. If victims clicked on a link, they were shown a short-lived authentication code they were invited to submit through the real Microsoft device login page, unwittingly giving criminals access to their email accounts without revealing their passwords. By stealing access tokens after a legitimate sign-in rather than going after passwords, attackers were able to surreptitiously gain persistent access to compromised Microsoft 365/Entra ID accounts. Chatbot for cybercrime The cybercrime platform also offered an AI-powered “analyst” chatbot that scanned compromised in-boxes to develop opportunities for financial fraud, such as business email compromise scams. “EvilTokens uses tailored phishing messages to trick victims into authorizing attacker access through Microsoft’s legitimate sign-in process,” explained Jason Rivera, global field CISO at cyber range platform provider SimSpace. “Once inside, AI analyzes the mailbox to identify who controls payments, which business relationships carry trust, and which invoices or transactions present opportunities.” Rivera, an ex-US Army threat intelligence officer, added: “It [EvilTokens] then recommends impersonation targets and helps draft fraudulent messages grounded in actual business conversations. Automated reconnaissance maps organizational permissions, while token refresh and inbox monitoring help maintain access and surface new opportunities.” Affected organizations ranged from wholesale distribution and construction to financial services, real estate, higher education, and healthcare, according to Microsoft. Organizations across North America, the UK, France, India, and Australia were targeted through the scam. Coinbase traced roughly $1.1 million in revenue from more than 700 distinct crypto addresses linked to the EvilTokens cybercrime operation. Takedown Microsoft was able to disrupt and dismantle the cybercrime operation after obtaining a US federal court order to seize 50 websites linked to EvilTokens and more than 150 associated domains as part of a coordinated takedown involving industry and law enforcement partners. UK police arrested two men (ages 32 and 38) suspected of running the technology and infrastructure behind EvilTokens. Each has been released on police bail pending further enquiries, including the forensic examination of seized digital devices. Device-code phishing defenses Omair Manzoor, founder, CEO, and chief hacker at ioSENTRIX, an expert in offensive security, said the “takedown was successful because the operators made a classic infrastructure mistake — centralizable domains and traceable crypto payments.” More sophisticated scams along the same lines are likely to follow, Manzoor warned. “Organizations need to assume that every compromised mailbox will be read and exploited by AI within minutes, not days,” Manzoor advised. “Device-code phishing defenses — conditional access policies restricting device code flow, short token lifetimes, and anomalous authentication alerting — need to move from best practice to baseline immediately.”

Read full story at CSO Online →