Microsoft dismantles EvilTokens, an AI chatbot built to run phishing attacks at scale

Microsoft's Digital Crimes Unit dismantled EvilTokens on September 22, a phishing-as-a-service platform that used an AI chatbot to run the entire attack chain — from compromising email accounts to drafting tailored impersonation scams. A US federal court authorized the seizure of 50 websites and the disabling of more than 150 additional domains tied to the operation, which Microsoft says compromised over 12,000 email inboxes across more than 10,000 organizations worldwide within months of its February 2026 launch.
Microsoft called it the Digital Crimes Unit's 40th court-authorized disruption overall, and its first against an end-to-end AI-enabled cybercrime service — a distinction that matters because it marks a shift from AI being used as one tool among many in a criminal operation to AI running the operation's core decision-making itself.
How the AI ran the attack chain
EvilTokens abused Microsoft's legitimate device-code sign-in flow, a mechanism designed to let devices without browsers (smart TVs, some IoT hardware) authenticate to Microsoft 365 accounts. Once operators had a foothold, the platform's built-in AI chatbot scanned compromised mailboxes to identify trusted contacts, then automatically drafted impersonation emails tailored to each victim's actual correspondence patterns — the kind of targeted social engineering that previously required a human operator studying each inbox by hand.
The service was sold openly on Telegram as a subscription: a $1,500 one-time signup fee plus $500 a month, with add-on packages running $600 to $1,000 for extras like bulk SMTP sending. Coinbase, one of Microsoft's partners in the takedown, traced roughly $1.1 million in revenue collected in cryptocurrency between October 2025 and June 2026, spread across more than 700 addresses on the Tron blockchain.
A coordinated, multi-partner takedown
The Digital Crimes Unit coordinated the disruption with Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, the Shadowserver Foundation, and TRM Labs — each contributing a different piece: network telemetry, cryptocurrency payment tracing, and cloud infrastructure data. That breadth reflects how phishing-as-a-service operations now span far more infrastructure than a single company can see on its own; tracking the money required a crypto-forensics firm, tracking the domains required a threat-intelligence nonprofit, and tracking the AI misuse required cooperation from OpenAI itself.
On the law enforcement side, London's Metropolitan Police Service arrested two men, aged 32 and 38, on September 11 in connection with the operation — arrests that predate the court-authorized infrastructure seizure by 11 days, suggesting investigators had identified suspects well before moving to take the platform itself offline.
Why this case sets a precedent
Every previous major phishing-as-a-service takedown targeted a service where AI, if present, played a supporting role. EvilTokens is different: Microsoft's own description frames the AI chatbot as making the core decisions about who to target, who to impersonate, and how to most effectively exploit each victim. That's a meaningful shift in what "disrupting cybercrime infrastructure" now means — taking down EvilTokens didn't just mean seizing servers, it meant taking an AI system out of a decision-making loop.
Organizations still using Microsoft's device-code authentication flow should treat this as a reminder to audit that specific sign-in path, since it's precisely the legitimate mechanism EvilTokens abused rather than a vulnerability Microsoft needs to patch.
Originally reported by Microsoft On the Issues. Read the original article for additional details.
View original source