Microsoft Takes Down EvilTokens AI-Powered Phishing Platform
Microsoft has successfully taken down EvilTokens, a cyber crime platform that leveraged AI to tailor phishing lures and analyze compromised inboxes. The service emerged on Telegram in February and allowed hackers to compromise over 12,000 inboxes at more than 10,000 organizations.
EvilTokens used an AI-style chatbot to help attackers decide who to target, impersonate, and exploit for maximum financial gain. The platform offered personalized lures and strategies for carrying out fraud, including drafting messages that impersonated trusted contacts.
Maryland-based Microsoft worked with the US District Court for the Eastern District of Virginia, as well as several other companies, to seize 50 websites used by the service. Over 150 domains tied to its supporting infrastructure were also seized.
UK authorities arrested two men suspected of being involved in the operation and released them on police bail while the investigation continues.