AI-Powered Phishing Operation Dismantled by Microsoft and Coinbase
A sophisticated phishing operation called EvilTokens was dismantled by Microsoft and Coinbase after it compromised over 12,000 inboxes worldwide. The AI-powered service used a subscription model, where customers paid $1,500 to initiate the service and $500 for recurring access. This allowed users to gain access to account information, understand its contents, and prepare impersonation campaigns without manual reconnaissance.
The operation relied on Microsoft's device-code authentication, which attackers initiated themselves and then sent to targets through phishing emails disguised as invoices or shared files. Victims who entered the code on Microsoft's legitimate website effectively approved the session waiting on the attacker's device.
EvilTokens' AI tools could translate and summarize messages, identify reporting lines and trusted contacts, surface pending invoices and wire-transfer conversations, and determine which employees had authority over payments. The platform also automated work that traditionally required attackers to spend hours reading correspondence and reconstructing how an organization moves money.