Microsoft Takedowns EvilTokens Phishing Platform Using AI
Microsoft has disrupted EvilTokens, a rapidly expanding phishing-as-a-service platform used by over 10,000 organizations worldwide. The platform was tied to more than 12,000 compromised Microsoft 365 inboxes across various countries including the US, Canada, UK, France, Australia, and India.
The platform's creators used AI throughout the attack chain, from developing the infrastructure to analyzing victims' mailboxes and crafting convincing impersonation schemes. EvilTokens also weaponized device-code phishing, a technique that surged 1,380% between late 2025 and early 2026, to hijack authenticated sessions without stealing passwords.
Microsoft seized 50 EvilTokens websites and disabled over 150 related domains, while two alleged operators were arrested in the UK. The disruption highlights the growing AI arms race between cybercriminals and defenders.
The platform's capabilities included account compromise, mailbox analysis, target selection, and fraud preparation tools, all accessible through a simple interface. Users could access these services for $1,500 initiation fee and a recurring $500 subscription via Telegram.