Microsoft Tackles AI-Powered Phishing Platform with Global Reach
Microsoft has successfully disrupted and dismantled EvilTokens, an AI-powered phishing-as-a-service (PhaaS) platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations worldwide.
The platform offered a subscription service with an initial sign-up fee of $1,500 and a monthly subscription fee of $500, marketed through Telegram channels. EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service, making it easier for attackers to use AI to scan compromised inboxes for opportunities for financial fraud.
The platform used device-code phishing, where victims were shown a short-lived authentication code they were invited to submit through the real Microsoft device login page, unwittingly giving criminals access to their email accounts without revealing their passwords. This allowed attackers to steal valid session tokens and gain persistent access to compromised Microsoft 365/Entra ID accounts.
A coordinated takedown involving industry and law enforcement partners resulted in the seizure of 50 websites linked to EvilTokens and over 150 associated domains, as well as the arrest of two men suspected of running the technology and infrastructure behind the platform.