Particle.news

Microsoft and Partners Disrupt EvilTokens AI‑Powered Phishing Service

Seizure of core domains removes the platform’s infrastructure.

Overview

  • Microsoft led an industry operation that, on Tuesday, seized about 50 websites and disabled more than 150 domains tied to EvilTokens and began notifying and helping remediate affected customers.
  • Two men in the U.K. were arrested in September in connection with the platform and released on police bail while investigations continue and partners shared evidence with law enforcement.
  • EvilTokens used an AI-style chatbot to read compromised inboxes, find trusted contacts and payment approvals, and craft tailored phishing lures that let attackers harvest persistent OAuth session tokens without stealing passwords.
  • Microsoft and partners tied the platform to roughly 12,000 compromised Microsoft inboxes across over 10,000 organizations, SpyCloud recovered about 8,700 affected accounts, and Coinbase traced about $1.1 million in cryptocurrency payments to the service.
  • Defenders are advised to block or restrict OAuth device-code flows, adopt phishing-resistant sign-in methods such as FIDO2 or passkeys, revoke suspicious sessions and verify payment-change requests out of band because copycat services and device-code scams are likely to reappear.