
Microsoft announced the disruption of EvilTokens, a subscription-based cybercriminal platform that leveraged artificial intelligence to facilitate mass account compromises. The platform, which was introduced through a Telegram channel in February, operated on a pricing model consisting of an initial $1,500 fee followed by monthly charges of $500. Through coordinated efforts with industry partners and using legal processes, Microsoft seized 50 websites and 150 additional domains associated with the operation. Law enforcement in the UK arrested two individuals in connection with the platform.
Accounts compromised through EvilTokens totaled 12,000, affecting organizations across 10,000 entities worldwide. The geographic distribution of victims showed the highest concentration in the United States, followed by Canada, the United Kingdom, Australia, India, and France. The targeted organizations operated across diverse sectors including wholesale distribution, construction, financial services, real estate, higher education, and healthcare.
The platform’s effectiveness derived from its automation of traditionally time-consuming aspects of account compromise and fraud schemes. At its core was an AI chatbot capable of analyzing victim inboxes to identify trusted contacts, payment authorizations, and sensitive responsibilities that could be exploited. The system could recommend fraud strategies and generate convincing impersonation messages designed to manipulate employees into authorizing fraudulent fund transfers to attacker-controlled accounts.
EvilTokens exploited the OAuth device code authentication process, a mechanism originally designed for devices with limited user interface capabilities such as televisions. The platform automated the delivery of spam containing malicious links directing users to pages with hidden scripts that interacted with Microsoft’s identity provider in real time. Users were prompted to enter device codes into Microsoft’s official login portal, unknowingly granting attackers access to their accounts. The sophisticated backend infrastructure enabled the operation to bypass traditional detection methods throughout the entire attack chain, from code generation through post-compromise activities.
Microsoft emphasized that the platform represented a significant evolution in account compromise techniques, as AI-assisted tools dramatically reduced the time required for attackers to analyze organizational structures and relationships. The company advised organizations to assume that compromised inboxes may be analyzed within minutes rather than days and recommended implementing strong identity protections while independently verifying sensitive requests through separate communication channels.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI