Microsoft Disrupts Global Phishing Service That Exploited OAuth Process
Microsoft's Digital Crimes Unit (DCU) has disrupted an AI-powered phishing service called EvilTokens, which targeted over 10,000 organisations worldwide and compromised more than 12,000 email accounts. The operation involved UK police arresting two suspects aged 32 and 38 on September 18th.
EvilTokens exploited Microsoft's OAuth 2.0 device-authorisation process to steal authentication tokens without directly stealing passwords. Attackers would send a phishing message with a device code that directed victims to Microsoft's genuine login page, where they were tricked into entering the code and authenticating.
The service was advertised on Telegram for $500 a month or $1,500 for lifetime access. Customers could also purchase additional tools, including anti-bot systems, bulk email capabilities, and Office 365 capture links. EvilTokens offered 44 customisable phishing kits designed to imitate services ranging from Microsoft and cloud identity platforms to document-signing, invoicing, voicemail, and eFax services.
Microsoft said the service used AI-powered tools to generate business email compromise messages tailored to information discovered in compromised mailboxes. The platform also used techniques such as HTML attachments, PDFs, multi-stage redirects, and fake CAPTCHA pages to evade detection.