Microsoft dismantles 'EvilTokens' AI phishing service in first AI takedown
Microsoft has dismantled EvilTokens, a subscription phishing service that used AI 'at every step of the attack chain', seizing 50 websites and disabling 150+ domains.
Microsoft has dismantled EvilTokens, a phishing-as-a-service platform that used AI “at every step of the attack chain”, in its Digital Crimes Unit’s first takedown of an end-to-end AI-enabled cybercrime service The Hacker News.
Under authorisation from the US District Court for the Eastern District of Virginia, Microsoft seized 50 websites and disabled more than 150 domains The Register. Health-ISAC joined as co-plaintiff, backed by Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation and TRM Labs backing the action TechNadu.
Tracked as Storm-2992, it compromised more than 12,000 Microsoft inboxes across 10,000 organisations in months. An AI chatbot analysed victims’ inboxes to spot trusted relationships and payment authorisations, then drafted tailored fraud emails. Victims entered device codes on Microsoft’s genuine login page — no password crossed the wire — and sessions could survive a password reset TechDefused.
Subscribers paid a $1,500 joining fee plus $500 a month; Coinbase traced roughly $1.1 million in crypto payments JBizNews.
The Metropolitan Police arrested two men, aged 32 and 38, earlier this month on suspicion of making articles for use in fraud and money laundering; both were released on bail pending further investigation Help Net Security. “Phishing services bring misery to thousands,” said Detective Inspector Serena D’Adamo, who led the investigation. Microsoft had reported the platform to the Met in August.
“No single organization could disrupt EvilTokens alone,” said Steven Masada, associate general counsel and general manager of the unit — its 40th court-authorised disruption since 2008.
Sources
More on this topic: all Technology stories
