September 27, 2026ADMIN

Microsoft disrupts EvilTokens platform linked to 12,000 compromised accounts

Microsoft disrupted EvilTokens, an AI-assisted phishing service linked to 12,000 compromised accounts across 10,000 organizations.

Microsoft disrupts EvilTokens platform linked to 12,000 compromised accounts

Microsoft says it led an industry-wide operation against EvilTokens, a subscription-based cybercrime platform that combined automated phishing infrastructure with an AI-style chatbot. Over several months, customers of the service compromised 12,000 Microsoft accounts belonging to 10,000 organizations worldwide.

The platform did more than help attackers gain access to email. It analyzed compromised inboxes, mapped trusted business relationships, identified employees involved in payments, and drafted convincing messages intended to redirect funds to attacker-controlled accounts.

What the EvilTokens service offered

EvilTokens appeared through a Telegram channel in February. Access cost an initial $1,500, followed by a recurring monthly fee of $500.

The service was designed to bring multiple stages of email-based fraud into one platform. Its capabilities included:

  • Sending large volumes of phishing emails
  • Tailoring lures to the profiles of targeted organizations
  • Capturing access to Microsoft accounts
  • Analyzing as many as 5,000 compromised emails at once
  • Identifying employees authorized to make large payments
  • Mapping relationships among employees, managers, suppliers, and customers
  • Recommending fraud scenarios and drafting impersonation messages

According to Microsoft, the central feature was an AI-style chatbot that examined inbox content for trusted relationships, payment authority, sensitive responsibilities, and situations in which fraud was more likely to succeed.

That analysis could help EvilTokens customers decide which compromised accounts offered the greatest potential payout. The platform could then produce follow-up emails that appeared to come from managers or other trusted contacts, with the goal of persuading employees to transfer money.

How the device code phishing attack worked

EvilTokens compromised accounts by abusing a legitimate OAuth process called device code authentication. This sign-in method is intended for televisions and other devices that do not have a practical interface for entering normal login credentials.

In a standard device code flow, the device displays a temporary code. The user opens an official login page in a browser on another device, enters the code, and authorizes the original device.

EvilTokens manipulated that workflow. Its customers sent spam containing malicious links or attachments. When a recipient interacted with the lure, a webpage used a hidden automation script to communicate with the person’s Microsoft identity provider in real time. SpyCloud, one of the security firms involved in the disruption, identified the provider as Microsoft Entra.

The script generated a code that would enroll a device controlled by the attacker. Victims were shown the code and instructed to copy it into Microsoft’s official device login portal. Because the user completed part of the process on a legitimate Microsoft page, the request could appear more credible.

Backend logic built with Node.js automated the process, from generating dynamic device codes through post-compromise activity. Microsoft said this approach also helped the operation avoid traditional detection systems that rely on known signatures or recurring patterns.

AI accelerated inbox analysis

Once attackers gained access to an account, EvilTokens helped them make sense of large volumes of email. Its AI-assisted features looked for organizational structures and financial responsibilities that would otherwise require extensive manual investigation.

The platform could identify:

  • Employees able to disburse significant amounts of money
  • Managers to whom those employees reported
  • Existing relationships with customers, suppliers, and other third parties
  • Plausible circumstances for requesting a payment or changing payment details

This reduced the time needed to prepare business email compromise attempts. Traditionally, an attacker might have to review thousands of messages to understand reporting lines and trusted relationships. Microsoft said AI-assisted tools substantially reduce that burden.

The result is a more compressed timeline between the initial account compromise and an attempted financial fraud. A criminal could quickly move from inbox access to a tailored request that reflects the victim organization’s actual personnel and business relationships.

Scale of the campaign and disruption

Microsoft attributed 12,000 compromised customer accounts across 10,000 organizations to users of EvilTokens. The largest concentration of affected accounts was in the United States, followed by Canada, the United Kingdom, Australia, India, and France.

Victims operated in several sectors, including:

  • Wholesale distribution
  • Construction
  • Financial services
  • Real estate
  • Higher education
  • Healthcare

Microsoft used legal processes and worked with a network of partners to seize 50 websites and 150 additional domains associated with the platform. The UK Metropolitan Police Service also arrested two men on suspicion of offenses allegedly connected to EvilTokens.

SpyCloud assisted with the disruption and published additional information about the affected organizations.

What organizations can learn from the operation

The EvilTokens case highlights how legitimate authentication features can be repurposed for phishing. A request that directs a user to an official sign-in portal is not necessarily safe, particularly when an unexpected message supplies a device code or asks the recipient to authorize unfamiliar hardware.

Microsoft advised organizations to assume that criminals may understand a compromised inbox within minutes rather than days. Strong identity controls and account monitoring remain important, but financial procedures also need safeguards beyond email.

Requests to change payment information, redirect funds, or approve unusual transactions should be independently confirmed through a trusted second channel. That verification should not rely on contact information provided in the potentially fraudulent request.

Conclusion

EvilTokens combined phishing automation, device code abuse, large-scale inbox analysis, and AI-generated social engineering in a single paid service. The disruption removed websites and domains used by the operation, but the case demonstrates how quickly attackers can turn email access into targeted financial fraud when automated analysis is available.

Original reporting: Ars


Originally reported by Ars.