Microsoft announced Tuesday it led an industry-wide effort to disrupt EvilTokens, a subscription-based platform that used an AI chatbot to automate large-scale email account compromises. The service had compromised 12,000 Microsoft accounts across 10,000 organizations globally over a few months.
EvilTokens, launched in February via Telegram, operated a straightforward business model: $1,500 upfront, $500 monthly. The economics reveal how easily criminal infrastructure scales when friction is removed. The service's core offering was an AI chatbot that analyzed victim inboxes to identify sensitive information—trusted relationships, payment authorizations, critical responsibilities—then recommended specific fraud strategies tailored to each target.
The chatbot could draft convincing follow-up emails impersonating trusted contacts, creating pretexts for company employees to transfer funds to attacker-controlled accounts.
The technical exploit leveraged OAuth device code authentication, a legitimate Microsoft process designed for input-limited devices like smart TVs. EvilTokens automated the dispatch of spam emails at scale. When users clicked malicious links or attachments, they reached a webpage running a hidden automation script that interacted with Microsoft Entra, Microsoft's identity provider, in real time. The script generated a device code for an attacker-controlled device. Victims then saw instructions to copy the code and enter it on the official Microsoft website—unknowingly authenticating the attacker's device and granting account access.
The highest concentration of victims was in the U.S. with significant compromise in Canada, the UK, Australia, India and France. Targeted sectors included wholesale distribution, construction, financial services, real estate, higher education and healthcare.
Microsoft seized 50 websites and 150 domains used by EvilTokens. Security firm SpyCloud assisted in identifying victims. Law enforcement followed: the UK's Metropolitan Police Service arrested two men suspected of offenses connected to the cybercrime platform.


