Microsoft Disrupts EvilTokens AI-Assisted Platform Behind 12,000 Account Compromises

Follow on Google Join Facebook Group WhatsApp Channel

TL;DR: Microsoft led an industry-wide disruption seizing 50 websites and 150 domains tied to EvilTokens, a subscription-based platform that compromised 12,000 accounts across 10,000 organizations. The operation abused legitimate OAuth device code authentication and deployed an AI chatbot to rapidly analyze inboxes and craft convincing payment fraud schemes. Law enforcement in the UK has arrested two suspects in connection with the platform.

Microsoft announced that it has spearheaded an industry-wide operation to disrupt EvilTokens, a subscription-based cybercrime platform that utilized an artificial intelligence chatbot to compromise 12,000 Microsoft accounts over the course of several months. The illicit platform enabled attackers to compromise accounts belonging to roughly 10,000 victim organizations worldwide.

First observed on a Telegram channel in February 2026, EvilTokens operated on a commercial model, charging subscribers an initial setup fee of $1,500 alongside a recurring monthly charge of $500. According to security researchers and company disclosures, the service provided an all-in-one platform that streamlined the technical hurdles of mass email account intrusion, post-compromise reconnaissance, and automated financial deception.

The Mechanics of EvilTokens: Phishing-as-a-Service

Security and finance professionals executing out-of-band verification procedures
Security specialists emphasize establishing secondary verification channels to validate payment alteration requests against AI-accelerated email fraud.

EvilTokens operated as a comprehensive platform designed to lower the barrier of entry for account intrusion. The service automated the distribution of high-volume spam campaigns. When recipients interacted with malicious links or attachments within those messages, they were directed to external web pages hosting hidden automation scripts.

These scripts communicated directly with the victim organization's identity management infrastructure in real time. Cybersecurity firm SpyCloud, which assisted Microsoft in the disruption effort, identified the targeted identity provider as Microsoft Entra. Built on a complex Node.js backend architecture, the platform avoided traditional signature- and pattern-based detection systems, enabling threat actors to coordinate operations from the initial lure to deep post-compromise exploitation.

How Attackers Abused OAuth Device Code Authentication

Rather than relying on basic credential harvesting pages, EvilTokens exploited a legitimate cloud authorization standard known as OAuth device code authentication. In standard business environments, device code flows are designed specifically for input-constrained devices, such as smart televisions, conference room screens, or media hardware that lack physical keyboards.

Under normal circumstances, an input-limited device presents an authorization code and instructs the user to open a browser on a secondary device, navigate to an official portal, and enter the code to complete authentication. EvilTokens manipulated this mechanism through real-time automation:

  • Victims clicked links that triggered background scripts to request a genuine device authentication code from Microsoft Entra.
  • The malicious interface displayed the generated device code and instructed the employee to enter it into Microsoft's official device login portal.
  • Because users entered the code directly into legitimate Microsoft login infrastructure, standard authentication checks were satisfied.
  • Once verified, the session authenticated a device under the attacker's control, granting persistent access to the victim's inbox without revealing credentials directly.

AI-Powered Inbox Analysis: 'Minutes, Not Days'

The defining element of EvilTokens was its integration of automated machine intelligence once inbox access was secured. Cybercriminals traditionally spent days or weeks manually reading archived correspondence to understand corporate reporting structures, vendor relationships, and billing procedures. EvilTokens automated this entire analytical phase.

The platform offered an administrative dashboard allowing attackers to analyze up to 5,000 compromised emails simultaneously. An embedded AI chatbot indexed messages to pinpoint personnel with financial disbursement authority, identify their direct managers, and map out active commercial agreements.

“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft reported. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”

By generating tailored, highly realistic follow-up emails, the tool facilitated sophisticated business email compromise (BEC) attacks, directing employees to wire corporate funds into bank accounts controlled by the attackers.

Global Scope and Targeted Industries

According to Microsoft's investigation, users of EvilTokens compromised 12,000 accounts distributed across 10,000 distinct organizations globally. Although entities in the United States represented the highest concentration of victims, substantial numbers were identified in Canada, the United Kingdom, Australia, India, and France.

The threat actors did not limit their focus to a single commercial niche. Documented victims spanned diverse operational sectors, including:

  • Wholesale distribution and logistics
  • Construction and engineering
  • Financial services
  • Real estate
  • Higher education
  • Healthcare organizations

Infrastructure Seizures and Law Enforcement Arrests

The coordinated takedown combined legal remedies, technical countermeasures, and international law enforcement intervention. Through court-authorized legal processes and partner cooperation, Microsoft dismantled the core operational infrastructure, seizing 50 websites and 150 domains used to host and direct EvilTokens services.

In parallel, the United Kingdom's Metropolitan Police Service took executive action, arresting two men on suspicion of offenses allegedly connected to the cybercrime platform. While the investigation remains ongoing, the coordinated legal and technical action effectively crippled the platform's ability to service existing subscribers.

Defensive Takeaways and Verification Best Practices

Microsoft noted that the emergence of platforms like EvilTokens represents a fundamental paradigm shift in enterprise identity defense. Threat actors are no longer constrained by human bandwidth when exploiting compromised email repositories.

“For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” Microsoft cautioned. “Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.”

Security teams are advised to monitor device code authentication events within Entra ID tenants, restrict device code authorization where unnecessary, and mandate strict out-of-band verification procedures for any modifications to supplier banking details or wire instructions.

Frequently Asked Questions

What was EvilTokens?

EvilTokens was a subscription-based cybercrime platform advertised via Telegram beginning in February 2026. For an initial $1,500 fee and $500 monthly, it provided automated tools for high-volume email compromise, inbox reconnaissance via an AI chatbot, and the generation of fraudulent payment lures.

How did EvilTokens compromise enterprise accounts?

The service abused OAuth device code authentication, a legitimate protocol intended for input-limited hardware. A background script requested an authorization code from Microsoft Entra and prompted the victim to enter it on the official Microsoft portal, successfully linking the attacker's device to the account.

What role did artificial intelligence play in the attacks?

EvilTokens utilized an AI chatbot capable of analyzing 5,000 emails simultaneously. It identified reporting lines, financial signing thresholds, and trusted suppliers, and drafted tailored impersonation messages to convince finance personnel to transfer funds.

Which regions and industries were affected?

Approximately 12,000 accounts across 10,000 organizations were compromised. The highest concentration was in the United States, followed by Canada, the UK, Australia, India, and France, impacting healthcare, financial services, construction, wholesale distribution, real estate, and higher education.

What actions were taken during the disruption?

Microsoft executed legal and technical actions to seize 50 websites and 150 domains associated with EvilTokens, with support from security firm SpyCloud. Concurrently, the UK Metropolitan Police Service arrested two individuals on suspicion of offenses allegedly linked to the operation.

What mitigation measures does Microsoft recommend?

Organizations are advised to strengthen identity monitoring, recognize that compromised inboxes can be comprehensively analyzed in minutes rather than days, and enforce strict secondary, out-of-band confirmation channels before approving payment alterations or unusual wire transactions.

Sources & Further Reading

Post a Comment

0 Comments