Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Mass Compromise and Post-Compromise of Accounts: A New Paradigm


Mass Compromise and Post-Compromise of Accounts: A New Paradigm

  • EvilTokens was a subscription-based scam platform that compromised 12,000 Microsoft accounts over a few months.
  • The platform provided an AI-style chatbot that could analyze a victim's inbox and identify trusted relationships, payment authorizations, and sensitive responsibilities.
  • The platform could recommend fraud strategies, including drafting messages that impersonated trusted contacts.
  • The highest concentration of compromised accounts was in the US, with other affected countries including Canada, UK, Australia, India, and France.
  • Microsoft seized 50 websites and 150 domains used to operate EvilTokens and arrested two men on suspicion of offenses.
  • The platform compromised accounts using device code authentication, which is designed for TVs and input-constrained devices.
  • Microsoft advised organizations to independently verify requests to change payment information or approve unusual transactions through a trusted second channel.


  • Microsoft has led an industry-wide disruption of a subscription-based scam platform called EvilTokens, which compromised 12,000 Microsoft accounts over a few-month span. The platform, introduced over a Telegram channel in February, charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers, making it easier for cybercriminals to access customer accounts.

    At the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed. The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.

    The highest concentration of compromised accounts was located in the US, with countries such as Canada, the UK, Australia, India, and France also being affected. The victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

    Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK's Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform.

    The platform compromised accounts using a legitimate OAuth process known as device code authentication, which is designed for TVs and input-constrained devices. EvilTokens provided customers with a platform that automated the sending of large numbers of spam, and users who clicked on malicious links or attachments in the emails were directed to a webpage running a hidden automation script that interacts with the user's Microsoft identity provider in real time to generate a code for enrolling a device belonging to the attacker.

    The technique allowed the process to work end to end, from the generation of dynamic device codes to post-compromise activities. A dashboard allowed users to tailor lures to the profiles of the organizations they targeted, and the platform largely automated the rest of the attack process. EvilTokens analyzed 5,000 compromised emails at a time, using AI to identify employees authorized to disburse large sums of money, the managers these employees reported to, and convincing scenarios under which the manager or others could persuade the employees to transfer money into what turned out to be attacker-controlled accounts.

    Microsoft said that EvilTokens represents a major shift in the mass compromise and post-compromise of accounts, and that once an inbox is compromised, criminals may understand its contents in minutes, not days. The company advised organizations to assume that once an inbox is compromised, criminals may understand its contents in minutes, not days, and to independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Mass-Compromise-and-Post-Compromise-of-Accounts-A-New-Paradigm-ehn.shtml

  • https://arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/

  • https://www.winzheng.com/en/article/microsoft-disrupts-eviltokens-ai-phishing


  • Published: Tue Sep 22 16:53:44 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us