Ethical Hacking News
Microsoft has taken down the EvilTokens device-code phishing service, a powerful cybercrime platform that used artificial intelligence (AI) to compromise email accounts and design roadmaps for financial fraud and scams. The service was linked to over 12,000 compromised email inboxes across over 10,000 organizations worldwide. The takedown of the EvilTokens service marks a significant development in the fight against cybercrime and highlights the growing use of AI-powered tools by threat actors.
Microsoft took down the EvilTokens device-code phishing service, a cybercrime platform using AI to compromise email accounts. The service was linked to over 12,000 compromised email inboxes across 10,000 organizations worldwide. The EvilTokens service offered AI-powered features, including mailbox analysis and impersonation mail. Threat actors used a multi-stage delivery pipeline to bypass traditional security measures. Around 200 threat actors subscribed to the service, including a man arrested by the Metropolitan Police Service.
In a significant development in the fight against cybercrime, Microsoft has taken down the EvilTokens device-code phishing service, a powerful cybercrime platform that used artificial intelligence (AI) to compromise email accounts and design roadmaps for financial fraud and scams. According to Microsoft, the EvilTokens service was used by threat actors to gain access to email accounts, register new devices, create malicious inbox rules, and exfiltrate sensitive email data.
The EvilTokens service was first documented by Huntress in March 2026 as a phishing-as-a-service (PhaaS) platform that abused the OAuth 2.0 device authorization flow to give attackers authenticated sessions with victim accounts without having to supply any credentials at their end. The service was found to have been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, indicating the service had gained widespread traction among threat actors in a short span of time.
The EvilTokens service was packaged into a single commercial service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation. The service was found to offer a range of AI-powered features, including AI-driven mailbox analysis, and drafting impersonation mail that follows.
The threat actor behind the EvilTokens service was found to have used a multi-stage delivery pipeline to bypass traditional email gateways and endpoint security through fake CAPTCHA checks and redirection chains that made use of high-reputation "serverless" platforms like Vercel, Cloudflare Workers, and AWS Lambda to blend in with legitimate enterprise cloud traffic and sidestep domain-blocklist triggers.
Microsoft collaborated with other partners, including Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs, to take down the EvilTokens service. The Metropolitan Police Service also arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial operation.
The takedown of the EvilTokens service is a significant development in the fight against cybercrime, and highlights the growing use of AI-powered tools by threat actors to compromise email accounts and design roadmaps for financial fraud and scams.
Related Information:
https://www.ethicalhackingnews.com/articles/Microsoft-Takedown-of-EvilTokens-A-Threat-to-Global-Cybersecurity-ehn.shtml
https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
Published: Tue Sep 22 12:52:46 2026 by llama3.2 3B Q4_K_M