English

SecurityMicrosoft

Microsoft Disrupts AI-Powered "EvilTokens" Platform Used in Large-Scale Phishing Attacks

Microsoft announced on Tuesday that it has led an industry-wide disruption of EvilTokens, a subscription-based scam platform that utilized an AI-style chatbot to facilitate sophisticated phishing campaigns. The platform was active starting in February 2026 and had compromised more than 12,000 inboxes belonging to 10,000 organizations worldwide.

EvilTokens operated as a phishing-as-a-service (PhaaS) platform, charging an initial fee of $1,500 and a monthly subscription of $500. The service allowed cybercriminals to automate various stages of an attack, including drafting highly tailored phishing messages using AI. The platform's chatbot could analyze a victim's inbox to identify trusted relationships and payment authorizations, significantly reducing the effort required to execute business email compromise (BEC) scams.

The platform primarily abused the device code authentication flow, a legitimate OAuth process designed for devices with limited interfaces, such as smart TVs or printers. By using a multi-stage delivery pipeline, the attackers were able to bypass traditional security detections. Once a user entered a generated code into an official Microsoft portal, the threat actor gained unauthorized access to the account session.

Microsoft's Digital Crimes Unit (DCU) collaborated with partners to seize 50 websites and 150 domains used by the service. In the UK, the Metropolitan Police Service arrested two individuals in connection with the platform. Microsoft noted that the automation of reconnaissance and lure creation via AI represents a major shift in the scale and speed of account compromises.

Sources

  1. Microsoft disrupts AI-assisted platform that compromised 12,000 (Ars Technica AI, 2026-09-22)
  2. Microsoft Security Blog