Breaking
Cyber CrimeDeveloping Story

Microsoft Cuts Off AI Phishing Platform

Microsoft and partners disrupted EvilTokens, an AI-assisted phishing service that compromised 12,000 accounts, seizing domains and prompting arrests.

··1 hour ago·5 min read
black and red laptop computer
Photo by FlyD on Unsplash

Over a few months, an AI-assisted subscription service quietly helped criminals compromise 12,000 Microsoft accounts belonging to 10,000 organizations worldwide. The platform, called EvilTokens, bridged the gap between bulk spam and convincing, context-aware fraud, enabling attackers to move from inbox access to payment theft with alarming speed. Microsoft announced Tuesday that it had led an industry-wide disruption of the operation, seizing infrastructure and prompting arrests in the UK.

A subscription service for inbox compromise

EvilTokens was introduced over a Telegram channel in February and operated as a paid platform. According to Microsoft, it charged an initial fee of $1,500 and then a recurring $500 charge each month after that. For that price, customers received a streamlined toolset for compromising email accounts at scale. The service automated most of the steps that would normally require hands-on effort, from sending phishing emails to analyzing the contents of compromised inboxes.

Unlike typical phishing kits, EvilTokens provided a comprehensive workflow. It helped customers analyze inboxes, select targets that would yield the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts. The platform effectively turned account takeover into a turnkey criminal service.

How the device code attack worked

At the heart of the compromise was a legitimate OAuth process known as device code authentication. This authentication method is designed for devices like smart TVs and input-constrained hardware that lack a full keyboard or browser. In normal use, the device displays a code and instructs the user to enter it into a browser on a separate device, which then authenticates the new device.

EvilTokens abused this flow by automating the sending of large numbers of spam. When a victim clicked a malicious link or attachment, they were directed to a webpage running a hidden automation script. That script interacted with the victim’s Microsoft identity provider in real time to generate a device enrollment code for an attacker-controlled device. The user would then see the code along with instructions to copy it and enter it into the official Microsoft device login portal. SpyCloud, a security firm that assisted in the disruption, identified the identity provider as Microsoft Entra.

The platform used complex backend logic written in Node.js to bypass traditional signature- or pattern-based detection. This allowed the attack to work end to end, from the generation of dynamic device codes to post-compromise activities. Microsoft has published more on the abuse of the OAuth process here.

AI chatbot as the engine of fraud

While the platform enabled access to email accounts, its central feature was an AI-style chatbot that analyzed victim inboxes and helped criminals identify opportunities for fraud. According to Microsoft, the chatbot could analyze a victim’s inbox to find trusted relationships, payment authorizations, sensitive responsibilities, and other circumstances where fraud was most likely to succeed. It could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to trick victims into taking action.

EvilTokens could process 5,000 compromised emails at a time. Using AI, it identified employees authorized to disburse large sums of money, the managers they reported to, and convincing scenarios under which a manager or other trusted party could persuade the employee to transfer money into attacker-controlled accounts. A dashboard allowed users to tailor lures to the profiles of targeted organizations.

“For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” Microsoft said. “Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.”

— Microsoft

Scope of the compromise

Microsoft said EvilTokens users compromised 12,000 customer accounts belonging to 10,000 organizations around the world. The highest concentration of victims was in the United States. The countries with the next-largest numbers were Canada, the UK, Australia, India, and France. Victim organizations spanned multiple sectors, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, which assisted in the disruption, has published more details about the victims here.

Disruption and arrests

Using a legal process and a network of partners, Microsoft seized 50 websites and 150 additional domains used to operate EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform. The operation involved collaboration across industry and law enforcement, marking a significant blow to the platform’s infrastructure.

What sets EvilTokens apart

Microsoft described EvilTokens as representing a major shift in the mass compromise and post-compromise of accounts. Normally, attackers spend considerable time sifting through thousands of emails to assemble an organization’s management chart, suppliers, customers, and other third-party relationships. AI-assisted tools drastically reduce that burden. What once took days of manual analysis can now be accomplished in minutes, giving criminals a faster path from initial access to financial fraud.

The platform’s ability to automate target selection and craft convincing follow-up messages means that even less-skilled criminals can execute sophisticated business email compromise campaigns. The subscription model further lowers the barrier to entry, making advanced capabilities available to a wider pool of actors.

Protecting against device code phishing

Device code authentication is a legitimate feature, but its abuse highlights the need for organizations to monitor for unusual sign-in patterns. Microsoft recommends strong identity protections and monitoring, but also stresses that organizations should independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel. This out-of-band verification can thwart fraud even if an inbox is compromised.

Security teams should review their logs for device code flow authentications, especially from unexpected locations or devices. Conditional access policies can restrict the use of device code flow where it is not needed. User education about unexpected device code prompts is also critical, as the attack relies on tricking users into entering codes on legitimate portals.

Why it matters: a new bar for phishing defense

The disruption of EvilTokens shows how quickly criminal services are incorporating AI to scale up and personalize attacks. For businesses, the incident suggests that traditional email security and employee training may not be enough when attackers can analyze an inbox in minutes and craft highly convincing messages. The case also underscores the value of cross-industry collaboration and law enforcement action in dismantling such platforms. While the seizure of domains and arrests may disrupt current operations, the underlying techniques—device code phishing and AI-assisted fraud—are likely to persist. Organizations may need to adopt stronger identity verification and out-of-band confirmation for sensitive transactions to stay ahead. As Microsoft noted, assuming an inbox compromise could happen at any moment and verifying payment changes through a separate trusted channel could be the difference between stopping fraud and suffering a costly loss.

#microsoft#evil tokens#device code phishing#ai phishing#account takeover

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories