Microsoft and Coinbase Take Down AI-Driven Phishing Operation
Microsoft and Coinbase have dismantled EvilTokens, an AI-powered phishing subscription service that compromised over 12,000 email inboxes across more than 10,000 organizations. The operation, which launched in February, used a technique called device-code phishing to target employees at various companies. For $1,500 upfront and $500 per month, subscribers received access to an AI analyst that read through hacked inboxes and identified the highest-probability marks for follow-up fraud emails.
The chatbot didn't write the phishing lure itself; it picked the victim after the door was already open. The operation's victims included wholesale distributors, construction firms, banks, real estate companies, universities, and hospitals. Microsoft tracks the group behind EvilTokens as Storm-2992.
A federal court order, two arrests in London, and blockchain tracing were necessary to shut down the operation. Coinbase's investigators followed cryptocurrency payments used by subscribers to pay their monthly fee, estimating that the operation generated around $1.1 million in revenue. The exchange's role was significant as it involved tracing the money.
Microsoft didn't do this alone; multiple companies and organizations contributed to the takedown, including Cloudflare, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and the Health-ISAC information-sharing group. This operation marks the first time that an end-to-end AI-enabled cybercrime service has been targeted by Microsoft's Digital Crimes Unit.