Microsoft Disrupts AI-Powered Cybercrime Platform EvilTokens
Microsoft's Digital Crimes Unit has disrupted EvilTokens, a cybercrime platform that utilized AI at every stage of its attack chain. This includes compromising email accounts, designing roadmaps for financial fraud and scams, and even recommending fraud strategies.
The platform's AI-style chatbot could analyze a victim's inbox to identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as circumstances where fraud was most likely to succeed. It also provided preset prompts to find wire-transfer discussions, locate vendor invoices, and determine the best people to impersonate.
EvilTokens was sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, combining account compromise, mailbox analysis, target selection, and fraud preparation in one service. The platform's capabilities were available through a ready-made interface, lowering the barriers at both ends of the attack chain.
The disruption of EvilTokens was a result of coordinated operational work across industry and law enforcement, with Microsoft working closely with partners such as Cloudflare, Coinbase, and OpenAI to act against key parts of the platform. The operation also demonstrated the value of rapid cooperation between private-sector investigators and law enforcement.