Microsoft Disrupts AI-Powered Cybercrime Platform EvilTokens
Microsoft has disrupted EvilTokens, a subscription-based cybercrime platform that used artificial intelligence to analyze stolen email and identify fraud opportunities. The service was launched in February and was linked to over 12,000 compromised inboxes at more than 10,000 organizations within months.
The operation removed a significant portion of EvilTokens' internet infrastructure, with Microsoft seizing 50 websites used to operate the service and disabling over 150 additional domains supporting it. The action was authorized by the U.S. District Court for the Eastern District of Virginia and coordinated with various companies and organizations, including Cloudflare, Coinbase, OpenAI, and TRM Labs.
The disruption was accompanied by arrests in Britain, where two men, aged 32 and 38, were arrested on September 11 on suspicion of offenses connected to EvilTokens' operation. They were released on conditional police bail while the investigation continues.
EvilTokens used AI to analyze email contents, identify payment processes, financial conversations, organizational roles, and trusted relationships. The platform could locate vendor invoices and wire-transfer discussions, identify employees able to move money, and recommend people for attackers to impersonate.