Policy

Microsoft disrupts EvilTokens AI cybercrime service

Microsoft has dismantled EvilTokens, an AI-powered cybercrime platform that compromised 12,000 accounts, highlighting how artificial intelligence is accelerating post-compromise email fraud.

Ars Technica AI10 hrs agoPolicy
Image: Ars Technica AI

Microsoft, alongside security firm SpyCloud and international law enforcement, has disrupted a subscription-based cybercrime platform called EvilTokens. The operation resulted in the seizure of 50 websites and 150 domains used to run the service, while the UK's Metropolitan Police Service arrested two men connected to the scheme. Launched on Telegram in February, EvilTokens charged cybercriminals an initial fee of $1,500 followed by a recurring monthly subscription of $500.

The platform targeted Microsoft Entra identity providers by abusing a legitimate OAuth process known as device code authentication. Attackers sent automated spam emails containing malicious links. When victims clicked, a hidden Node.js automation script generated a dynamic device code. Victims were then tricked into entering this code into the official Microsoft login portal, granting attackers full account access. This complex backend logic allowed the platform to bypass traditional signature-based security detection.

Once inside, EvilTokens used an AI-style chatbot to analyze up to 5,000 compromised emails at a time. The AI identified employees authorized to transfer funds, mapped out organizational hierarchies, and drafted highly convincing phishing messages impersonating trusted contacts. In total, the platform compromised 12,000 accounts across 10,000 organizations globally, with the highest concentration in the United States, followed by Canada, the United Kingdom, Australia, India, and France. Affected sectors spanned wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

For security practitioners, EvilTokens represents a paradigm shift in how quickly attackers can exploit compromised accounts. Traditionally, mapping out an organization's relationships and finding high-value targets took days of manual email review. With AI, this process is reduced to minutes. Microsoft warns that organizations must assume attackers will immediately understand an inbox's contents upon compromise. To defend against these rapid, AI-driven threats, defenders must enforce robust identity protections and mandate out-of-band verification for any sensitive financial transactions.

This is our own summary of reporting by Ars Technica AI

More in Policy