Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform (thehackernews.com) 43
Microsoft's security blog describes the fight against a new "AI-powered cybercrime platform" offering phishing-as-a-service, with AI-tailored lures and analyses of compromised inboxes (to identify high-value targets). The site compromised more than 12,000 inboxes in over 10,000 organizations around the world, compromising business accounts "at scale" with automated attacks and prebuilt phishing templates. AI tools could even sift through a victim's mailbox to help engineer better phishing messages.
To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC (a non-profit helping health sector organizations share cyber threat information).
"Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud told The Hacker News.
From Microsoft's security blog: Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action... Microsoft worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination... While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service...
Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft's Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service.
Sometimes stolen tokens were used to give new devices access to a victim's inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor's session and grants access to their account...) But "AI was not simply helping attackers write more convincing messages," says another Microsoft blog post. "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible." The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works... Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers," locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.
Investigators found evidence that large portions of EvilTokens had been "vibe coded," with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.
To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC (a non-profit helping health sector organizations share cyber threat information).
"Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud told The Hacker News.
From Microsoft's security blog: Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action... Microsoft worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination... While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service...
Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft's Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service.
Sometimes stolen tokens were used to give new devices access to a victim's inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor's session and grants access to their account...) But "AI was not simply helping attackers write more convincing messages," says another Microsoft blog post. "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible." The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works... Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers," locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.
Investigators found evidence that large portions of EvilTokens had been "vibe coded," with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.
We want YOU for our Great Army of STUPIDS (Score:2)
No, AC. No one wants you. There is such a thing as a sock puppet too stupid.
For this story "We" is Microsoft, but really it's a broader thing, and it goes back to the math. So many people hate the criminals and would even be glad to help shut down the criminals, but Microsoft doesn't want any help on that scale. That would involve training people to be wiser and more cautious, but Microsoft prefers suckers who will obey the ads and send money. In Microsoft's case, that's for software that is so buggy and ho
Um ... (Score:5, Funny)
AI-Powered
I think you mean, SI-Powered [slashdot.org] /s (*heavy-sigh*)
Re: (Score:2)
That's the only way I can read this that makes any sense IRL. Obviously wishful thinking.
Re: (Score:2)
Microsoft updates will be discontinued?
That's the only way I can read this that makes any sense IRL. Obviously wishful thinking.
Yes. I've had two out of band updates that were served up BOHICA style after pausing updates. And at a bad time. I also had an update that wouldn't let me log into the laptop at all - it disabled the camera, wouldn't even show a password login, after clicking to enter the password, wouldn't do a PIN. Wouldn't accept the login reset questions.
The good news is that despite all that, despite it being completely unusable, it showed several ads on the login screen. So it didn't brick it totally. 8^( Took a
Re: (Score:1)
just you ? no one else is having these catastrophic errors, just you...Perhaps you should let someone else fix your machine. Win 11 sucks but quit making up lame shit...it makes you look stupid.
Be you, having serious comprehensive cognition problems. You are the human equivalent of Windows 11.
Re: (Score:2)
You should stop clicking on dodgy animal porn sites and perhaps your windows machine wouldnâ(TM)t be running so much spyware
Oh summer child - this is my work computer, and I'd be fired if they found anything sketchy on it.
However, I do have a concern - It is rather concerning that the first thing you went to is bestiality pR0n. I think you might be projecting, and you should probably get therapy.
Re: uh (Score:1, Insightful)
Re: uh (Score:2)
Making excuses for Microsoft and doubting that they fucked up a users' computer when they are infamous for that is cuck shit.
Re: (Score:2)
Making excuses for Microsoft and doubting that they fucked up a users' computer when they are infamous for that is cuck shit.
I certainly have no reason to make shit up. If our animal lover were to check my posts, he's see that I've documented many cases, showing just how bad it is. Even Microsoft admits W11 is a hot mess of dog puke. Not links for you, you already know the truth - but since I already replied to our lad, here's something for him to read. Perhaps he can tell Microsoft that they too are full of bullshit, and that no one who knows anything about computers has ever had a problem, so they do not need to make any chang
Re: (Score:2)
Stories like yours are generally either a) bullshit or b) your own fault and I am just t asking out which one you are
Oh, How about both. Sorry My friend who has a thing for animals, I only touched the surface. I teach classes for digital communications via RF. Have done so for years. You'll have a computer, a soundcard interface, and CAT control of the radio that you need to get working together. Back in Windows 7 days, in two classes we had everyone running in two classes, then started in on the details of the software, students gaining expertise.
In Windows 10 days, there were some hiccups, but eventually things settle
Re: (Score:2)
Re: (Score:2)
Re: uh (Score:2)
Lol off topic your Microsoft stock will not ever love you back
Changes Over Time (Score:5, Informative)
Microsoft email: Never before have there been so many Microsoft email security measures. Never before has email been so inconvenient for the end user due to Microsoft security measures. Never before Microsoft Exchange Online have there been so many breached email accounts.
It's kind of staggering. Like watching more people pile onto an overloaded, decrepit, sinking Thai boat, and then acting surprised when it sinks of capsizes.
Every other month, a new improved security system. Strong passwords, password rotation, MFA, phish resistant MFA, conditional access policies, passwordless, passkeys... 'This one will rule them all.' Yet, every day we see more Business Email Compromises(BEC) on Microsoft's platform than ever before.
Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It's always Microsoft. Hmmm.
Re:Changes Over Time (Score:5, Informative)
Not that other operations don't have their issues: Gmail is overrun with spammers and phishers, for example. But those might be fixed given some attention by the right people. Microsoft will never be fixed.
Re: (Score:3)
I've been designing, building, and running email systems for a very long time. And one of the things I've observed is that it is impossible to secure any email system running on Microsoft platforms. I've watched colleagues -- sincere, smart, dedicated, hardworking, diligent colleagues -- try over and over and over again...and all of them have failed. ALL OF THEM.
My "solution" has been to send the emails and send them to a different address. The only time I go to my Exchange is to empty it out every once in a while.
But yeah, Exchange is an embarrassment
Re: (Score:2)
Re: (Score:1)
Microsoft email: Never before have there been so many Microsoft email security measures. Never before has email been so inconvenient for the end user due to Microsoft security measures. Never before Microsoft Exchange Online have there been so many breached email accounts.
It's kind of staggering. Like watching more people pile onto an overloaded, decrepit, sinking Thai boat, and then acting surprised when it sinks of capsizes.
Every other month, a new improved security system. Strong passwords, password rotation, MFA, phish resistant MFA, conditional access policies, passwordless, passkeys... 'This one will rule them all.' Yet, every day we see more Business Email Compromises(BEC) on Microsoft's platform than ever before.
Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It's always Microsoft. Hmmm.
This! The only good thing here is the people complaining that Linux and MacOS are just as insecure as Windows, have shut up.
After being forced onto Exchange, I decided to capture the email and send it to another address.
At this point, I am firmly convinced the only solution is to completely rewrite Windows in Unix. Possibly Linux, close enough. Then we might not have this utter embarrassment of a brittle, non-secure Operating system. Because Windows is reaching a singularity moment.
There is a reaso
Re:Changes Over Time (Score:4)
Not many businesses use Yahoo or Apple for email, hence the absence of BEC events.
Self-hosted servers get hacked all the damn time. I see the spam they send.
cPanel is vulnerable as hell, I've seen it hacked many times. It also sucks.
Microsoft is one of the largest providers for business email. That they are a primary target is expected.
Re: (Score:2)
Email would be totally secure if not for the retard users who can't NOT click on ANYTHING. You can't secure an environment populated by entitled morons. All you can do there is clean up after them and move on.
Re: (Score:3)
Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It's always Microsoft. Hmmm.
None of those other mail platforms are fully integrated with the OS running on the overwhelming majority of enterprise desktops. The reward for successfully breaching an MS tool is an order of magnitude greater than any of those others.
That's not to defend Microsoft - their products weren't consistently that great to begin with, but they have been rapidly and radically deteriorating over the past 7 years. But there's no useful comparison between Exchange and any of those other mail platforms. There's plenty
Alternete Headline (Reality-based) (Score:2)
Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform.
(An hour later, a new headline emerges)
Microsoft Discovers It's own Microsoft Update Was the Culprit, Fires Marketing Manager
I've seen it. (Score:2)
Yes, but: how was this possible? (Score:2)
That's nice. But how was this facilitated in the first place? (1) Domain registrars who will sell scammers as many domains as they want. (2) Hosting providers who will host obvious phishers/scammers/typosquatters as long as they pay the bills (3) Cryptocurrency ope
Re: (Score:2)
Phishing as a service (Score:2, Troll)
Re: (Score:3)
Apparently Microsoft doesn't want the competition...
Funny!
No wait.. Insightful!
No, wait...Sad.
Slashdot needs a "sad" mod specifically for Microsoft Windows 11.
shorter headline (Score:2)
Can also be used for censorship (Score:2)
https://battlepenguin.com/poli... [battlepenguin.com]
https://battlepenguin.com/poli... [battlepenguin.com]
Re:Can also be used for censorship (Score:5, Interesting)
Seniors who grew up in the 1950's did not "get what they deserved" for clicking on a link or answering a message. A lot of them still think they have to answer the phone when it rings, or read emails they get from strangers, just in case it could be one of their friends or family asking for help or telling them something important. Billions of dollars are stolen from senior citizens and people with cognitive problems. The platforms that exploit them for profit should also be held responsible for protecting them from even worse actors than themselves.
The rest of us who have corporate training not to click on phishing emails should know better. But still, a few clever phishing attacks succeed out of thousands that fail, and that's all they need. I would consider it an obligation to shut down phishing sites proactively rather than waiting for people to report them. Same goes for the fake sites that pull content from retail sites, claim to sell it at ridiculous discounts so they can harvest credit cards.
150 sites/domains is a drop in the bucket though. They should be proyactively killing domains instead of just raking in money and letting criminal enterprises do whatever they want. Let the real criminal enterprises like Meta and alphabet have all the fun.
Abusing OAuth Device Code Flow (Score:2)
The Device Authorization Grant, Microsoft's OAuth extension built for browser-less devices like smart TVs, was abused in a phishing campaign reaching victims through a Mailchimp Mandrill redirect link with a Base64-encoded destination.
The link led to a fake Adobe-branded page that silently requested a real device code from Microsoft's
No Law enforcement? (Score:3)
"Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC"
Under what authority did these private organizations seize domains? I am not sure how I feel about corporations acting as law enforcement. No wait, actually I am very sure how I feel about that.
Ok I read the Article, The blurb really should have mentioned "The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia"
"Microsoft also notified affected customers" (Score:2)