Skip to content
MarketsIndicesCommoditiesFXRates
Technology

Microsoft dismantles AI phishing platform EvilTokens

Microsoft has dismantled EvilTokens, an artificial intelligence platform that compromised thousands of email accounts to generate phishing attacks.

Microsoft dismantles AI phishing platform EvilTokens

Microsoft has dismantled an artificial intelligence scam platform that compromised 12,000 email accounts belonging to 10,000 organisations worldwide in a few months.

microsoft-visitors-center-redmond
Microsoft visitor centre in Redmond

The platform, known as EvilTokens, used an artificial intelligence chatbot to analyse the compromised inboxes and prepare new fraudulent messages. The service operated as a subscription, allowing clients to launch sophisticated phishing campaigns without building the infrastructure themselves.

Microsoft is a multinational technology corporation that develops software and cloud computing services. The company regularly investigates and disrupts cybercriminal operations that abuse its platforms and target its users.

Phishing is a form of cybercrime where attackers use deceptive messages to trick victims into revealing sensitive information or authorising payments. Artificial intelligence tools can make these messages appear more convincing by mimicking natural language and personalising the content.

Subscription service on Telegram

According to Ars Technica, EvilTokens was advertised on the Telegram messaging application from February. Clients paid an initial fee of $1,500, followed by a monthly subscription of $500 for the complete service.

Telegram is a cloud-based instant messaging service known for its privacy features. Security researchers frequently observe illicit tools, stolen data and hacking services being advertised in channels on the platform.

Once the attackers gained access to an email account, the artificial intelligence chatbot began analysing the inbox. Microsoft said the software searched for trusted relationships, payment authorisations and sensitive responsibilities.

The chatbot then used this genuine information to generate fraudulent messages. This approach allowed the attackers to create highly credible phishing attempts based on the victim's actual business relationships and frequent suppliers.

Device login mechanism

The initial access relied on a legitimate Microsoft login mechanism used for televisions and gaming consoles. The attackers initiated a request that prompted the victim to visit microsoft.com/link and enter a code.

Victims who entered the code believed they were linking their own device. Instead, they granted the attackers valid authorisation to access their email account without the need to install malicious software.

This valid authorisation gave the chatbot free rein to review existing conversations and prepare the next scam. The attackers effectively bypassed traditional security measures that monitor for unrecognised devices or suspicious software installations.

International victims

The highest concentration of affected accounts was in the United States. The platform also targeted victims in Canada, the United Kingdom, Australia, India and France.

The compromised organisations spanned multiple industries. The victims included businesses in wholesale distribution, construction, financial services, real estate, higher education and health.

The takedown operation resulted in the seizure of 50 websites and 150 domains related to EvilTokens. The cybersecurity firm SpyCloud, which specialises in preventing account takeovers, also participated in the disruption effort.

The British Metropolitan Police Service arrested two men allegedly linked to the platform. The force, often referred to as Scotland Yard, is responsible for law enforcement in Greater London.

Microsoft took legal action to dismantle the infrastructure used by the service's clients. The operation disrupted what was effectively cybercrime packaged as a subscription service.

Related

Leave a comment

Your email address will not be published. Required fields are marked *