Microsoft Disrupts EvilTokens Phishing Operation Using AI-Powered Scams
Microsoft has dismantled a phishing tool called EvilTokens that leveraged artificial intelligence to compromise email accounts and devise strategies for committing financial scams. The company led by Satya Nadella is tracking those responsible for its development and support under the designation Storm-2992.
Statistics from Microsoft show that this malicious artifact has been linked to over 12,000 compromised email inboxes across more than 10,000 organizations worldwide, indicating its popularity among cybercriminals. The platform used AI chatbots to analyze victims' inboxes and assist criminals in identifying trusted relationships, payment authorizations, and confidential responsibilities.
According to Steven Masada, Deputy General Counsel and General Manager of Microsoft's Digital Crimes Unit, the platform could even recommend fraud strategies, such as drafting messages that impersonated trusted contacts. EvilTokens was sold under a PhaaS model on Telegram since mid-February, offering customers self-hosted templates and AI-driven features to automate BEC (Business Email Compromise) workflows.