Microsoft says it has disrupted EvilTokens, an AI-powered subscription platform that helped cybercriminals compromise 12,000 Microsoft accounts and target businesses with payment fraud.
Microsoft announced Tuesday that it led an industry-wide operation against the fraud platform, which used AI chatbots to streamline account takeovers, inbox analysis, victim selection, and phishing campaigns.
EvilTokens launched through a Telegram channel in February. The service charged an initial fee of $1,500 followed by a recurring monthly fee of $500. Customers could use the platform to compromise large numbers of email accounts, analyze their inboxes, identify targets likely to produce the biggest payouts, and draft follow-up messages designed to trick employees into transferring funds to attacker-controlled accounts.
EvilTokens helped criminals turn compromised accounts into fraud campaigns
“EvilTokens helped cybercriminals gain access to email accounts, but at the heart of the service was an AI-style chatbot that analyzed victims’ inboxes and helped criminals identify trust relationships, payment authorizations, confidential responsibilities, and other situations where fraud was most likely to be successful,” Microsoft said.
Microsoft said the platform could also recommend deception strategies, including messages that impersonated trusted contacts and persuaded victims to take specific actions.
According to Microsoft, EvilTokens users compromised 12,000 customer accounts belonging to 10,000 organizations worldwide. The United States had the highest concentration of affected accounts, followed by Canada, the United Kingdom, Australia, India, and France.
The affected organizations included businesses and institutions in wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Security firm SpyCloud, which supported the disruption operation, has published additional details about the victims here.
Microsoft seized more than 150 EvilTokens domains
Using legal processes and a network of partners, Microsoft seized 50 websites and more than 150 domains used to operate EvilTokens.
The Metropolitan Police also arrested two men on suspicion of connections to the criminal platform.
How the account compromises worked
The account takeovers relied on a legitimate OAuth process known as device code authentication. This authentication method is designed for TVs and other devices with limited input, where users cannot complete the normal login process directly.
In a device code flow, the device displays a code and instructs the user to enter it in a browser on another device. Once the user completes the process, the original device is authorized. EvilTokens abused this legitimate workflow to help attackers gain access to Microsoft accounts.
Source: arstechnica.com


