MICROSOFT says it led an industry-wide operation to disrupt EvilTokens, a subscription-based cybercrime platform that used an AI-style chatbot to help compromise 12,000 Microsoft customer accounts belonging to 10,000 organisations. Introduced through Telegram in February, the service reportedly charged $1,500 initially and $500 a month.
Its tools analysed compromised inboxes, identified valuable targets and relationships, and drafted convincing messages designed to trick employees into transferring money to attacker-controlled accounts. Victims were concentrated in the US, followed by Canada, the UK, Australia, India and France, and included organisations in distribution, construction, financial services, property, higher education and healthcare.
The attacks abused Microsoft Entra’s legitimate device-code authentication process. EvilTokens sent bulk phishing messages containing links or attachments that led to a page running hidden automation. Victims were shown a device code and directed to enter it on Microsoft’s official login portal, unknowingly authenticating an attacker-controlled device. Backend Node.js logic generated dynamic codes and supported activity after compromise, helping evade traditional signature- and pattern-based detection.
The platform could analyse up to 5,000 emails at once, using AI to identify payment authorisers, reporting lines and plausible fraud scenarios.
Using legal action and partners, Microsoft seized 50 websites and 150 additional domains linked to the service. The Metropolitan Police Service arrested two men on suspicion of offences allegedly connected to the platform. Microsoft advised organisations to verify payment or account-change requests through a separate trusted channel, stressing that AI-assisted tools can allow criminals to understand a compromised inbox in minutes rather than days.