news.mlab.sh
Back to the feed
threat-intel

AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

High
Summary

Microsoft disrupted EvilTokens, an AI-powered phishing platform used by cybercriminals to target over 10,000 organizations globally. The platform leveraged device code phishing and AI to compromise email accounts, and two men were arrested in the UK as part of the takedown.

Microsoft announced on Tuesday that it had taken down EvilTokens, an AI-powered phishing platform used by cybercriminals to target numerous organizations worldwide. The platform emerged in February 2026 and, according to Microsoft, had already compromised more than 12,000 email accounts at over 10,000 organizations, including those in the US, Canada, the UK, Australia, India, and France.

EvilTokens utilized device code phishing, a method that targets devices lacking standard login methods, such as TVs and printers. The process required users to enter a short code displayed on the device into a web browser session on a separate device. Cybercriminals initiated this authentication flow and provided the code to the targeted user via a phishing lure. If the user completed the authentication process using the attacker’s code, they granted the attacker access to their account without needing to provide a password.

EvilTokens facilitated this process, making it easier for cybercriminals to obtain access tokens that could provide persistent access to email accounts. The platform employed AI throughout the attack chain, including to create phishing emails tailored to specific targets and to determine who to impersonate to maximize financial gain. It offered 44 different themes for malicious emails and phishing pages.

Once access was gained to an account, AI helped EvilTokens users sift through victims’ inboxes to extract valuable data. Microsoft believes the platform itself was also coded using AI. To access and use EvilTokens, cybercriminals had to pay $1,500 for initial access and a $500 monthly fee.

Microsoft seized 50 websites used to run the service and disabled more than 150 other domains linked to the platform’s infrastructure. In addition to the technical disruption, two men, Felix Utomi and Waidi Segun Adams, were arrested in the United Kingdom, suspected of being linked to the operation of EvilTokens. Microsoft named the suspects in a complaint filed as part of its efforts against the phishing platform, which also targeted five unnamed individuals.

SpyCloud, TRM Labs, Coinbase, Health-ISAC, Cloudflare, OpenAI, Railway, and The Shadowserver Foundation also contributed to the EvilTokens takedown.

Read the full article at SecurityWeek