
Microsoft announced on Tuesday that it had led an industry-wide disruption of EvilTokens, a subscription-based platform that used artificial intelligence to facilitate the compromise of approximately 12,000 Microsoft accounts over several months. The platform, which was introduced through a Telegram channel in February, operated on a paid subscription model charging $1,500 for initial access and $500 monthly thereafter.
EvilTokens functioned as an end-to-end service designed to streamline the process of compromising email accounts at scale. The platform’s core feature was an AI-powered chatbot that could analyze victims’ inboxes to identify trusted business relationships, payment authorization patterns, and sensitive responsibilities. This analysis helped attackers determine which individuals and scenarios were most susceptible to financial fraud schemes. The platform also automated the drafting of fraudulent messages that impersonated trusted contacts to manipulate victims into transferring funds to attacker-controlled accounts.
The compromised accounts belonged to 10,000 organizations distributed across multiple countries, with the highest concentration in the United States. Other significantly affected regions included Canada, the United Kingdom, Australia, India, and France. Victim organizations spanned various sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Working with partners and using legal processes, Microsoft seized 50 websites and 150 additional domains associated with the operation. The UK’s Metropolitan Police Service arrested two men suspected of involvement with the platform.
The attack method exploited a legitimate OAuth authentication process called device code authentication, typically designed for devices with limited input capabilities such as televisions. EvilTokens automated the distribution of spam emails containing malicious links or attachments that directed users to pages running hidden scripts. These scripts interacted with Microsoft’s identity provider in real time to generate device codes for attacker-controlled devices. Victims would be prompted to enter these codes into official Microsoft login portals, completing the account compromise. Microsoft emphasized that organizations should implement strong identity protections, conduct independent verification of unusual financial requests through separate communication channels, and recognize that compromised inboxes may be analyzed by attackers within minutes rather than days.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI