HomeSecurityEvilTokens: Microsoft dismantles AI-powered phishing platform

EvilTokens: Microsoft dismantles AI-powered phishing platform

Microsoft has announced the dismantling of EvilTokens, an advanced “phishing-as-a-service” (PhaaS) platform that leveraged artificial intelligence to automate key stages of cyberattacks. According to the company, the service was linked to the breach of more than 12,000 Microsoft 365 accounts in over 10,000 organizations worldwide, revealing how cybercrime is gradually turning into an organized, subscription-based service.

Article image: Microsoft's EvilTokens takedown sheds light on state of AI-powered cybercrime

The case is particularly significant because EvilTokens was not limited to stealing credentials. The platform could help its clients gain access to accounts, analyze the contents of mailboxes, and identify business opportunities for fraud.

A complete cybercrime “chain” as a service

EvilTokens has reportedly been operating since February 2026 as a subscription service, bringing together in a single environment tools that until recently required significant technical knowledge.

The initial registration cost around $1,500, while the monthly subscription was $500. The service was promoted through Telegram, following the model increasingly common in the modern underground cybercrime economy.

See also: Fake LastPass Authenticator installer exploits Microsoft signed driver

At the center was a dashboard and chatbot, through which users could manage different stages of an attack. As Microsoft points out, activities that required expertise in cloud identities, social engineering, and financial fraud were made accessible through a ready-made interface.

The phishing did not ask for the password

One of the most interesting elements of the campaign was the utilization of Microsoft's OAuth 2.0 device-code authentication flow

Instead of the attackers asking the victim to enter their password on a fake page, the phishing message led the user through a process that seemed legitimate. The victim received a temporary password and was asked to enter it on Microsoft's official device login page

In this way, the user could complete a real authentication process, without realizing that they were essentially granting attackers access via a valid session token.

This is critical, as the attack shifts the focus from password theft to the abuse of legitimate identification mechanisms.

AI chatbot that "reads" corporate emails

The real power of EvilTokens, however, lay in the next stage. After an account was compromised, the built-in AI chatbot could analyze the contents of the mailbox and identify information useful for financial fraud.

The AI ​​could search for details about invoices, payments, business relationships, finance managers, and past conversations, so attackers didn't have to manually sift through thousands of messages.

Based on this data, the system could suggest potential impersonation targets and help craft messages that looked like real business communications , a development that significantly enhances Business Email Compromise (BEC) attacks .

Unicode invisible character mechanism

From phishing to financial fraud

EvilTokens' model shows why a corporate email breach can have consequences far greater than simply losing access to an account.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Microsoft: New bug bounty program for AI-powered Bing

An attacker who gains access to a mailbox can monitor conversations, understand a company's internal processes, and wait for the right moment to intervene in a real financial transaction.

AI speeds up this process, as it can act as an analyst business data. This reduces the human cost required for criminals and increases the ability to target multiple organizations at once.

Thousands of organizations in many countries

According to Microsoft, the victims came from different industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

The activity expanded to North America, the United Kingdom, France, India and Australia, demonstrating the international nature of the infrastructure.

Coinbase also identified approximately $1.1 million in revenue linked to more than 700 different cryptocurrency addresses associated with the EvilTokens operation.

Microsoft seized dozens of EvilTokens

The takedown was carried out following a US federal court order, which allowed Microsoft to seize 50 websites and more than 150 related domains.

The operation also involved partners from the cybersecurity industry and law enforcement. Two men, aged 32 and 38, were arrested in the United Kingdom on suspicion of operating the service's technology infrastructure. They have been released on police bail, while investigations and forensic examination of the digital devices seized continue.

See also: Microsoft: Tycoon2FA dismantling reduced phishing attacks by 92%

EvilTokens: Microsoft dismantles AI-powered phishing platform

What should organizations do?

The EvilTokens case highlights the need for stronger defenses against device-code phishing. Organizations should leverage Conditional Access that restrict the use of device-code authentication where possible, enforce strict rules for applications and devices, and monitor for unusual authentication attempts.

Equally important is the rapid detection of suspicious sessions and the limited lifetime of access tokens. In the event of an account breach, changing the password is not enough. It is necessary to revoke active sessions and tokens, check the applications that have been granted permissions, and look for forwarding rules or other mechanisms that may have been installed in the mailbox.

The disruption of EvilTokens is a significant blow to this infrastructure, but the business model behind PhaaS remains. Artificial intelligence lowers the technical barrier for criminals and allows for the automation of tasks that previously required human expertise.

The most important conclusion for businesses is that a compromised mailbox can now be almost immediately exploited as a source of information for targeted fraud. Protection, therefore, cannot be based only on preventing password theft, but must cover the entire lifecycle of identity, tokens and access to corporate data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS