All stories
AI

Microsoft Disrupts AI-Powered EvilTokens Phishing Platform

Microsoft's Digital Crimes Unit successfully dismantled EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 customer inboxes globally, marking its first action against an end-to-end AI-enabled cybercrime service.

By TECH NEWS Editorial·Source:Ars Technica·4 min read·1h ago

This content was summarized and interpreted by AI; it may contain errors — please verify accuracy with the original sources. Learn more

Share

Listen to this story

0:00 / 0:00
Microsoft Disrupts AI-Powered EvilTokens Phishing Platform

Microsoft has successfully disrupted EvilTokens, an AI-powered phishing-as-a-service (PhaaS) platform that compromised over 12,000 Microsoft customer email inboxes across more than 10,000 organizations globally since its launch in February 2026. This coordinated takedown, led by Microsoft's Digital Crimes Unit (DCU) and involving partners like Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs, represents the DCU's first action against an end-to-end AI-enabled cybercrime service. The operation, which included seizing 50 websites and disabling over 175 domains linked to EvilTokens, also saw the arrest of two men in the UK on September 11, 2026, suspected of operating the platform.

EvilTokens distinguished itself by leveraging artificial intelligence at every stage of the attack chain, moving beyond mere AI-assisted message crafting to automate complex financial fraud schemes. The platform, marketed through Telegram channels for an initial fee of $1,500 and a $500 monthly subscription, offered a sophisticated suite of tools that significantly lowered the barrier to entry for cybercriminals. Its core feature was an AI-style chatbot that could analyze compromised inboxes to identify trusted relationships, payment authorizations, and other sensitive details, then design intricate roadmaps for fraud and scams. This meant AI was not just generating convincing phishing lures—it was actively helping attackers decide who to target, who to impersonate, and how to maximize financial exploitation. For instance, the AI could summarize emails, surface financial conversations, map organizational roles, and even draft fraudulent messages impersonating trusted contacts.

The platform primarily exploited Microsoft's OAuth 2.0 device authorization flow, a legitimate authentication method designed for devices with limited input capabilities. By abusing this flow, EvilTokens enabled attackers to steal session tokens, bypassing multi-factor authentication (MFA) and gaining persistent access to Microsoft 365/Entra ID accounts without ever needing the victim's password. This "device code phishing" technique was further enhanced by EvilTokens' "just-in-time" dynamic code generation, which addressed the traditional 15-minute expiration window of device codes by generating a fresh code only when a victim interacted with a malicious landing page, drastically increasing the attack's success rate. Once access was gained, the platform’s AI capabilities would conduct reconnaissance through Microsoft Graph, mapping organizational structures and permissions to facilitate lateral movement and identify further fraud opportunities.

The disruption of EvilTokens underscores a critical shift in the cybercrime landscape: the industrialization of AI-powered attacks. While phishing-as-a-service (PhaaS) platforms have existed for years, EvilTokens represents a new generation where AI moves beyond simple automation to intelligent decision-making and strategic planning for criminals. This elevates the threat from mass, generic attacks to highly personalized, context-aware campaigns that are far harder for traditional defenses to detect. The service’s ability to analyze inboxes and recommend fraud strategies in minutes, a task that previously required experienced human social engineers hours or days, dramatically compresses the time defenders have to react. This development is particularly concerning as AI-driven social engineering can now be scaled across multiple channels in real-time, producing hyper-personalized messages, cloned voices, and even deepfake video impersonations that blur the lines between reality and deception.

Compared to earlier PhaaS offerings like Evilginx or Gopish, which focused on credential interception or reverse proxying, EvilTokens' innovation lies in its end-to-end AI integration and its abuse of the device code flow for persistent, MFA-bypassing access. This makes it a "premium product" targeting organized crime groups seeking a complete automated fraud pipeline, rather than a commodity tool for volume attacks. The platform's rapid adoption, compromising over 12,000 inboxes within months of its February 2026 launch, highlights the effectiveness and demand for such sophisticated tools. Victims were concentrated in the United States, Canada, the United Kingdom, Australia, India, and France, spanning sectors from financial services and healthcare to real estate and higher education. Coinbase, which assisted in the investigation, traced approximately $1.1 million in revenue for EvilTokens from over 700 distinct crypto addresses, demonstrating the significant financial gains facilitated by the platform.

Looking ahead, the disruption of EvilTokens serves as a stark warning and a blueprint for future threats. While this specific platform has been dismantled, the underlying model it demonstrated—combining stolen access with AI capable of understanding and exploiting compromised data—will undoubtedly persist and evolve. Cybersecurity will increasingly become a battle of AI versus AI, with both attackers and defenders leveraging advanced algorithms. Defenders must anticipate a future where AI agents automate entire attack lifecycles, from reconnaissance and vulnerability scanning to exploitation and data exfiltration, with minimal human input. This necessitates a shift from reactive security to proactive, AI-powered, unified, and automated detection and response platforms. Organizations must also prioritize disabling device-code authentication when unnecessary and enforcing robust, hardware-bound authentication methods like FIDO2, which can render even sophisticated token-harvesting campaigns inert. The imperative is clear: assume that once an inbox is compromised, criminals, aided by AI, can understand and exploit its contents in minutes, not days, demanding a fundamental re-evaluation of post-compromise response strategies and continuous investment in AI-driven defensive capabilities.