{"id":9559,"date":"2026-09-22T20:40:34","date_gmt":"2026-09-22T20:40:34","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9559"},"modified":"2026-09-22T20:40:34","modified_gmt":"2026-09-22T20:40:34","slug":"microsofts-eviltokens-takedown-sheds-light-on-state-of-ai-powered-cybercrime","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9559","title":{"rendered":"Microsoft\u2019s EvilTokens takedown sheds light on state of AI-powered cybercrime"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Microsoft has hailed its success in disrupting <a href=\"https:\/\/www.csoonline.com\/article\/4153742\/eviltokens-abuses-microsoft-device-code-flow-for-account-takeovers.html\">EvilTokens<\/a>, an AI-powered a <a href=\"https:\/\/www.csoonline.com\/article\/514515\/what-is-phishing-examples-types-and-techniques.html\">phishing-as-a-service<\/a> (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide.<\/p>\n<p class=\"wp-block-paragraph\">Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to those capabilities, with a $1,500 initial sign-up fee and $500 monthly subscription, marketed through Telegram channels.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service,\u201d Microsoft explains in a <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2026\/09\/22\/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime\/\">post about the takedown<\/a>. \u201cCapabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The cybercrime platform abusing Microsoft\u2019s OAuth 2.0 device-code authentication flow to steal valid session tokens through device code phishing. If victims clicked on a link, they were shown a short-lived authentication code they were invited to submit through the real Microsoft device login page, unwittingly giving criminals access to their email accounts without revealing their passwords.<\/p>\n<p class=\"wp-block-paragraph\">By stealing access tokens after a legitimate sign-in rather than going after passwords, attackers were able to surreptitiously gain persistent access to compromised Microsoft 365\/Entra ID accounts.<\/p>\n<h2 class=\"wp-block-heading\">Chatbot for cybercrime<\/h2>\n<p class=\"wp-block-paragraph\">The cybercrime platform also offered an AI-powered \u201canalyst\u201d chatbot that scanned compromised in-boxes to develop opportunities for financial fraud, such as <a href=\"https:\/\/www.csoonline.com\/article\/4128950\/what-does-business-email-compromise-look-like.html\">business email compromise<\/a> scams.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEvilTokens uses tailored phishing messages to trick victims into authorizing attacker access through Microsoft\u2019s legitimate sign-in process,\u201d explained Jason Rivera, global field CISO at cyber range platform provider SimSpace. \u201cOnce inside, AI analyzes the mailbox to identify who controls payments, which business relationships carry trust, and which invoices or transactions present opportunities.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Rivera, an ex-US Army threat intelligence officer, added: \u201cIt [EvilTokens] then recommends impersonation targets and helps draft fraudulent messages grounded in actual business conversations. Automated reconnaissance maps organizational permissions, while token refresh and inbox monitoring help maintain access and surface new opportunities.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Affected organizations ranged from wholesale distribution and construction to financial services, real estate, higher education, and healthcare, according to Microsoft. Organizations across North America, the UK, France, India, and Australia were targeted through the scam.<\/p>\n<p class=\"wp-block-paragraph\">Coinbase traced roughly $1.1 million in revenue from more than 700 distinct crypto addresses linked to the EvilTokens cybercrime operation.<\/p>\n<h2 class=\"wp-block-heading\">Takedown<\/h2>\n<p class=\"wp-block-paragraph\">Microsoft was able to disrupt and dismantle the cybercrime operation after obtaining a US federal court order to seize 50 websites linked to EvilTokens and more than 150 associated domains as part of a coordinated takedown involving industry and law enforcement partners.<\/p>\n<p class=\"wp-block-paragraph\">UK police arrested two men (ages 32 and 38) suspected of running the technology and infrastructure behind EvilTokens. Each has been released on police bail pending further enquiries, including the forensic examination of seized digital devices.<\/p>\n<h2 class=\"wp-block-heading\">Device-code phishing defenses<\/h2>\n<p class=\"wp-block-paragraph\">Omair Manzoor, founder, CEO, and chief hacker at ioSENTRIX, an expert in offensive security, said the \u201ctakedown was successful because the operators made a classic infrastructure mistake \u2014 centralizable domains and traceable crypto payments.\u201d<\/p>\n<p class=\"wp-block-paragraph\">More sophisticated scams along the same lines are likely to follow, Manzoor warned.<\/p>\n<p class=\"wp-block-paragraph\">\u201cOrganizations need to assume that every compromised mailbox will be read and exploited by AI within minutes, not days,\u201d Manzoor advised. \u201cDevice-code phishing defenses \u2014 conditional access policies restricting device code flow, short token lifetimes, and anomalous authentication alerting \u2014 need to move from best practice to baseline immediately.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9560,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9559","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9559"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9559"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9559\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9560"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}