Microsoft Dismantles AI-Powered Phishing Service EvilTokens
A recent collaboration between Microsoft and law enforcement agencies in the UK and US led to the takedown of an AI-powered phishing service called EvilTokens.
The platform, which was allegedly run by two UK residents, Felix Utomi and Waidi Segun Adams, enabled the theft of OAuth authentication tokens and used artificial intelligence to identify the most profitable compromised email inboxes.
Maintaining access to the platform varied from $500 to $1000 per month, depending on the features offered. The service used AI models from Groq and OpenAI to analyze hacked email inboxes and identify potential targets for wire transfer fraud and other financial crimes.
A civil complaint filed by Microsoft and Health-ISAC alleged that EvilTokens facilitated 'millions of dollars' worth' of financial crimes, victimizing at least 106 organizations across Virginia. The platform's developers used specially designed prompts to feed into the AI models, instructing them to flag anyone who could move money, hijack active payment threads, and locate vendor invoices for cloning.
The operation was dismantled after Microsoft worked with British and US officials to seize 50 websites and over 150 additional domains tied to its supporting infrastructure. The company's threat intelligence unit has identified the kit's developer as Storm-2992.