Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Microsoft Disrupts EvilTokens: A New Era of Mass Compromise and Post-Compromise Attacks




Microsoft has disrupted a subscription-based scam platform called EvilTokens, which compromised 12,000 Microsoft accounts over a few-month span. The platform used an AI chatbot to analyze victim's inboxes and identify trusted relationships, payment authorizations, and sensitive responsibilities. Microsoft seized 50 websites and 150 more domains used to operate EvilTokens and arrested two men on suspicion of offenses allegedly connected to the crime platform. The disruption highlights the evolving nature of cybercrime and the importance of strong identity protections and monitoring.

  • Microsoft has disrupted a subscription-based platform called EvilTokens, which was used to facilitate mass email account attacks.
  • The platform, which used AI-style chatbots, charged a one-time fee of $1,500 and a monthly recurring charge of $500.
  • The platform provided a service to compromise email accounts in large numbers, making it easier for attackers to gain access to sensitive information.
  • Microsoft seized 50 websites and 150 domains used to operate EvilTokens and arrested two men on suspicion of offenses connected to the crime platform.
  • The attackers used complex backend logic to bypass traditional detection methods and provided a dashboard to tailor lures to targeted organizations.
  • Microsoft warned that compromised inboxes can be accessed in minutes, highlighting the importance of strong identity protections and monitoring.
  • The rise of AI-assisted tools like EvilTokens underscores the evolving nature of cybercrime and the need for organizations to stay vigilant and take proactive measures to protect themselves.



  • Microsoft's latest move in the fight against cybercrime has brought attention to a subscription-based platform called EvilTokens, which has been compromised to facilitate mass email account attacks. The platform, which was introduced over a Telegram channel in February, charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers, making it easier for attackers to gain access to sensitive information.

    At the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities. The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action. This AI-assisted tool has greatly reduced the time it takes for attackers to sift through thousands of emails to assemble the organization's management chart, suppliers, customers, and other relationships with third parties.

    The disruption operation, led by Microsoft, involved seizing 50 websites and 150 more domains used to operate EvilTokens. The UK's Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform. The attackers used a legitimate OAuth process known as device code authentication, which is designed for TVs and input-constrained devices. However, the attackers found a way to bypass traditional signature- or pattern-based detection, using complex backend logic in the platform.

    The platform also provided a dashboard that allowed users to tailor lures to the profiles of the organizations they targeted. The platform analyzed 5,000 compromised emails at a time, using AI to identify employees authorized to disburse large sums of money, the managers these employees reported to, and convincing scenarios under which the manager or others could persuade the employees to transfer money into what turned out to be attacker-controlled accounts.

    The disruption of EvilTokens represents a major shift in the mass compromise and post-compromise of accounts. Microsoft warned that once an inbox is compromised, criminals may understand its contents in minutes, not days. Therefore, strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.

    The rise of AI-assisted tools like EvilTokens highlights the evolving nature of cybercrime. As AI technology advances, it is becoming increasingly easier for attackers to gain access to sensitive information. It is essential for organizations to stay vigilant and take proactive measures to protect themselves against these types of attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Microsoft-Disrupts-EvilTokens-A-New-Era-of-Mass-Compromise-and-Post-Compromise-Attacks-ehn.shtml

  • https://arstechnica.com/security/2026/09/microsoft-disrupts-ai-assisted-platform-that-compromised-12000/


  • Published: Tue Sep 22 18:44:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us