Microsoft announced Tuesday it led an industry-wide effort to disrupt EvilTokens, a subscription-based scam platform that utilized an AI chatbot to compromise 12,000 Microsoft accounts across 10,000 organizations globally.
The service, introduced in February via Telegram, charged an upfront fee of $1,500 and $500 monthly. The platform streamlined large-scale account compromises by automating the targeting and social engineering process.
EvilTokens' core offering was an AI chatbot that analyzed victim inboxes to identify trusted relationships, payment authorizations and sensitive responsibilities—pinpointing situations where fraud was most likely to succeed. The platform then recommended fraud strategies and drafted messages impersonating trusted contacts to manipulate victims into taking action.
The highest concentration of victim organizations was in the U.S. followed by Canada, the UK, Australia, India and France. Targets spanned wholesale distribution, construction, financial services, real estate, higher education and healthcare. Security firm SpyCloud assisted Microsoft in the disruption operation.
Compromises occurred through device code authentication, a legitimate OAuth process designed for input-constrained devices like smart TVs. This method requires users to enter a code from one device into a browser on a separate, trusted device to authenticate.
EvilTokens automated large-scale spam campaigns. When users clicked malicious links or attachments, they were redirected to a webpage running a hidden automation script. That script interacted with Microsoft Entra, Microsoft's identity provider, in real time to generate a device enrollment code. Users unknowingly entered this code into an official Microsoft domain, granting attackers access to their accounts.
Microsoft seized 50 websites and 150 additional domains used to operate EvilTokens through a legal process involving a network of partners. The UK's Metropolitan Police Service arrested two men on suspicion of offenses related to the platform.