started · updated
Microsoft and partners dismantle AI-powered EvilTokens phishing network
Microsoft, Cloudflare, and Coinbase, in coordination with international law enforcement, have dismantled EvilTokens, an AI-powered phishing-as-a-service platform. The operation targeted Microsoft 365 accounts by exploiting OAuth 2.0 device-code authentication to bypass multi-factor authentication (MFA).
EvilTokens operated via a subscription model on Telegram, charging a $1,500 setup fee and a $500 monthly fee. The platform utilized an integrated AI chatbot to analyze compromised inboxes, identify high-value targets, and draft convincing phishing lures to facilitate business email compromise. The service reportedly compromised over 12,000 email inboxes across more than 10,000 organizations in 79 countries, with high concentrations of victims in the US, Canada, UK, Australia, India, and France.
As part of the disruption, authorities seized 50 websites and disabled over 150 domains. In London, the Metropolitan Police arrested two men in connection with the operation. Financial forensics conducted by Coinbase traced approximately $1.1 million in illicit revenue across more than 700 deposit addresses.
Entities
Cloudflare · Coinbase · Digital Crimes Unit · EvilTokens · Health-ISAC · London · Metropolitan Police · Metropolitan Police Service · Microsoft
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 5 SOURCES] The service operated on a subscription model with a $1,500 setup fee and $500 monthly fee. www.ad-hoc-news.de · www.blogspan.net · cryptobriefing.com · infosecu.technews.tw
- [● 6 SOURCES] Two men were arrested in London in connection with the operation. www.blogspan.net · cryptobriefing.com · blogs.microsoft.com · infosecu.technews.tw · iguru.gr
- [○ 1 SOURCE] Coinbase traced approximately $1.1 million in illicit revenue across more than 700 deposit addresses. cryptobriefing.com
- [● 8 SOURCES] Microsoft disrupted the EvilTokens AI-powered phishing-as-a-service platform. www.ad-hoc-news.de · www.blogspan.net · cryptobriefing.com · blogs.microsoft.com · australiancybersecuritymagazine.com.au · +2 more
- [● 7 SOURCES] The platform compromised over 12,000 email inboxes across more than 10,000 organizations in 79 countries. cryptobriefing.com · australiancybersecuritymagazine.com.au · infosecu.technews.tw · iguru.gr · www.ad-hoc-news.de · +2 more
- [● 4 SOURCES] The attackers used OAuth 2.0 device-code authentication to bypass multi-factor authentication. www.ad-hoc-news.de · www.blogspan.net · cryptobriefing.com
- [● 5 SOURCES] EvilTokens utilized an AI chatbot to analyze compromised inboxes and identify high-value fraud targets. www.blogspan.net · cryptobriefing.com · blogs.microsoft.com · australiancybersecuritymagazine.com.au
- [● 5 SOURCES] The operation resulted in the seizure of 50 websites and the disabling of over 150 domains. www.blogspan.net · cryptobriefing.com · blogs.microsoft.com · infosecu.technews.tw