Forgot your password?
typodupeerror
Microsoft Crime Security

Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform (thehackernews.com) 43

Microsoft's security blog describes the fight against a new "AI-powered cybercrime platform" offering phishing-as-a-service, with AI-tailored lures and analyses of compromised inboxes (to identify high-value targets). The site compromised more than 12,000 inboxes in over 10,000 organizations around the world, compromising business accounts "at scale" with automated attacks and prebuilt phishing templates. AI tools could even sift through a victim's mailbox to help engineer better phishing messages.

To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC (a non-profit helping health sector organizations share cyber threat information).

"Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud told The Hacker News.

From Microsoft's security blog: Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action... Microsoft worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination... While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service...

Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft's Digital Crimes Unit (DCU) facilitated a coordinated disruption of infrastructure used to operate the EvilTokens service.

Sometimes stolen tokens were used to give new devices access to a victim's inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor's session and grants access to their account...) But "AI was not simply helping attackers write more convincing messages," says another Microsoft blog post. "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible." The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works... Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers," locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.

Investigators found evidence that large portions of EvilTokens had been "vibe coded," with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform

Comments Filter:
  • Um ... (Score:5, Funny)

    by fahrbot-bot ( 874524 ) on Wednesday September 23, 2026 @04:12AM (#66348062)

    AI-Powered

    I think you mean, SI-Powered [slashdot.org] /s (*heavy-sigh*)

  • Changes Over Time (Score:5, Informative)

    by SlashbotAgent ( 6477336 ) on Wednesday September 23, 2026 @06:05AM (#66348140)

    Microsoft email: Never before have there been so many Microsoft email security measures. Never before has email been so inconvenient for the end user due to Microsoft security measures. Never before Microsoft Exchange Online have there been so many breached email accounts.

    It's kind of staggering. Like watching more people pile onto an overloaded, decrepit, sinking Thai boat, and then acting surprised when it sinks of capsizes.

    Every other month, a new improved security system. Strong passwords, password rotation, MFA, phish resistant MFA, conditional access policies, passwordless, passkeys... 'This one will rule them all.' Yet, every day we see more Business Email Compromises(BEC) on Microsoft's platform than ever before.

    Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It's always Microsoft. Hmmm.

    • Re:Changes Over Time (Score:5, Informative)

      by Arrogant-Bastard ( 141720 ) on Wednesday September 23, 2026 @08:04AM (#66348228)
      I've been designing, building, and running email systems for a very long time. And one of the things I've observed is that it is impossible to secure any email system running on Microsoft platforms. I've watched colleagues -- sincere, smart, dedicated, hardworking, diligent colleagues -- try over and over and over again...and all of them have failed. ALL OF THEM. Not even Microsoft, which has for all practical purposes infinite money and infinite personnel, has managed to pull it off. Given this 100% failure rate, I'm convinced that it can't be done.

      Not that other operations don't have their issues: Gmail is overrun with spammers and phishers, for example. But those might be fixed given some attention by the right people. Microsoft will never be fixed.
      • I've been designing, building, and running email systems for a very long time. And one of the things I've observed is that it is impossible to secure any email system running on Microsoft platforms. I've watched colleagues -- sincere, smart, dedicated, hardworking, diligent colleagues -- try over and over and over again...and all of them have failed. ALL OF THEM.

        My "solution" has been to send the emails and send them to a different address. The only time I go to my Exchange is to empty it out every once in a while.

        But yeah, Exchange is an embarrassment

      • How long does google have to go unfixed before you'll put it in the same category? At some point, you either have to do that or accept the same "might be fixed" possibility for Microsoft.
    • Microsoft email: Never before have there been so many Microsoft email security measures. Never before has email been so inconvenient for the end user due to Microsoft security measures. Never before Microsoft Exchange Online have there been so many breached email accounts.

      It's kind of staggering. Like watching more people pile onto an overloaded, decrepit, sinking Thai boat, and then acting surprised when it sinks of capsizes.

      Every other month, a new improved security system. Strong passwords, password rotation, MFA, phish resistant MFA, conditional access policies, passwordless, passkeys... 'This one will rule them all.' Yet, every day we see more Business Email Compromises(BEC) on Microsoft's platform than ever before.

      Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It's always Microsoft. Hmmm.

      This! The only good thing here is the people complaining that Linux and MacOS are just as insecure as Windows, have shut up.

      After being forced onto Exchange, I decided to capture the email and send it to another address.

      At this point, I am firmly convinced the only solution is to completely rewrite Windows in Unix. Possibly Linux, close enough. Then we might not have this utter embarrassment of a brittle, non-secure Operating system. Because Windows is reaching a singularity moment.

      There is a reaso

    • by sabbede ( 2678435 ) on Wednesday September 23, 2026 @10:23AM (#66348428)
      I just delt with a gmail breach.

      Not many businesses use Yahoo or Apple for email, hence the absence of BEC events.
      Self-hosted servers get hacked all the damn time. I see the spam they send.
      cPanel is vulnerable as hell, I've seen it hacked many times. It also sucks.
      Microsoft is one of the largest providers for business email. That they are a primary target is expected.

    • by Archfeld ( 6757 )

      Email would be totally secure if not for the retard users who can't NOT click on ANYTHING. You can't secure an environment populated by entitled morons. All you can do there is clean up after them and move on.

    • Nobody is talking about breaches at GMail, AOL/Yahoo, Apple, cPanel, and self hosted servers. It's always Microsoft. Hmmm.

      None of those other mail platforms are fully integrated with the OS running on the overwhelming majority of enterprise desktops. The reward for successfully breaching an MS tool is an order of magnitude greater than any of those others.

      That's not to defend Microsoft - their products weren't consistently that great to begin with, but they have been rapidly and radically deteriorating over the past 7 years. But there's no useful comparison between Exchange and any of those other mail platforms. There's plenty

  • Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform.

    (An hour later, a new headline emerges)

    Microsoft Discovers It's own Microsoft Update Was the Culprit, Fires Marketing Manager

  • ""Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud told The Hacker News."

    That's nice. But how was this facilitated in the first place? (1) Domain registrars who will sell scammers as many domains as they want. (2) Hosting providers who will host obvious phishers/scammers/typosquatters as long as they pay the bills (3) Cryptocurrency ope
    • Even if you build a house out of flash paper, the arsonist who lights the match is still the one at fault for the fire.
  • Apparently Microsoft doesn't want the competition...
    • Apparently Microsoft doesn't want the competition...

      Funny!

      No wait.. Insightful!

      No, wait...Sad.

      Slashdot needs a "sad" mod specifically for Microsoft Windows 11.

  • Microsoft eliminates their competition
  • Such coordinated efforts by so many big tech companies might seem like a good thing in regards to security, but this honestly scares the fuck out of me. Sure they can take down a phishing cite (honestly a lot of those people deserve what they got; they clicked on the link or executed the code). But what about legitimate and legal websites where people just say things others don't like? I've written about this before:

    https://battlepenguin.com/poli... [battlepenguin.com]

    https://battlepenguin.com/poli... [battlepenguin.com]
    • by toxonix ( 1793960 ) on Wednesday September 23, 2026 @04:18PM (#66348914)

      Seniors who grew up in the 1950's did not "get what they deserved" for clicking on a link or answering a message. A lot of them still think they have to answer the phone when it rings, or read emails they get from strangers, just in case it could be one of their friends or family asking for help or telling them something important. Billions of dollars are stolen from senior citizens and people with cognitive problems. The platforms that exploit them for profit should also be held responsible for protecting them from even worse actors than themselves.

      The rest of us who have corporate training not to click on phishing emails should know better. But still, a few clever phishing attacks succeed out of thousands that fail, and that's all they need. I would consider it an obligation to shut down phishing sites proactively rather than waiting for people to report them. Same goes for the fake sites that pull content from retail sites, claim to sell it at ridiculous discounts so they can harvest credit cards.

      150 sites/domains is a drop in the bucket though. They should be proyactively killing domains instead of just raking in money and letting criminal enterprises do whatever they want. Let the real criminal enterprises like Meta and alphabet have all the fun.

  • How did the "Go With the Flow" campaign abuse Microsoft's OAuth Device Code Flow to compromise accounts? [levelblue.com]

    The Device Authorization Grant, Microsoft's OAuth extension built for browser-less devices like smart TVs, was abused in a phishing campaign reaching victims through a Mailchimp Mandrill redirect link with a Base64-encoded destination.

    The link led to a fake Adobe-branded page that silently requested a real device code from Microsoft's /devicecode endpoint, then had victims enter that code on Micros
  • by Holi ( 250190 ) on Wednesday September 23, 2026 @03:22PM (#66348860)

    "Microsoft worked with other organizations, including Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, Shadowserver Foundation, and TRM Labs to Health-ISAC"

    Under what authority did these private organizations seize domains? I am not sure how I feel about corporations acting as law enforcement. No wait, actually I am very sure how I feel about that.

    Ok I read the Article, The blurb really should have mentioned "The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia"

  • And these notification emails are often a joke. Who did they notify in your organisation exactly? What should be be looking for in terms of sender or subject. Some previous "notifications" have been the equivalent of filing it in a locked filing cabinet in an old toilet with a "beware of the leopard" sign on the door... MS's excuse is "well we told you", but they actually emailed role accounts which never, ever check their email.

Real Users are afraid they'll break the machine -- but they're never afraid to break your face.

Working...