Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft, in collaboration with several partners, successfully took down EvilTokens, a sophisticated phishing-as-a-service (PaaS) platform utilizing AI to compromise email accounts and facilitate financial fraud. The service, developed and operated by threat actor Storm-2992, allowed criminals to gain access to over 12,000 email inboxes across 10,000 organizations worldwide, leveraging AI to analyze compromised mailboxes, draft targeted phishing emails, and bypass security measures. The operation resulted in the seizure of 50 websites and the disabling of 150 domains, representing a significant disruption to the threat landscape.
Microsoft announced the takedown of EvilTokens, a device code phishing service that leveraged artificial intelligence to compromise email accounts and enable widespread financial fraud. The operation, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved collaboration with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and TRM Labs.
What happened
EvilTokens operated as a commercially available PaaS platform, offering a turnkey solution for business email compromise (BEC) and invoice fraud. The threat actor, Storm-2992, utilized AI to automate key aspects of the attack chain, including analyzing compromised mailboxes in over twenty languages to identify valuable conversations and drafting targeted phishing emails. The service lowered the technical barrier to entry for aspiring cybercriminals, allowing them to develop advanced toolkits and perpetrate fraud at scale.
Technical details
The service employed a multi-stage delivery pipeline to bypass email gateways and endpoint security, utilizing
