Interestana
Home/News/Microsoft Disrupts AI-Powered EvilTokens Phishing Service
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Disrupts AI-Powered EvilTokens Phishing Service

Microsoft Disrupts AI-Powered EvilTokens Phishing Service

Microsoft announced on Tuesday the successful takedown of the EvilTokens device code phishing service, a sophisticated operation that utilized artificial intelligence (AI) at every stage of its attack chain. This action, authorized by the U.S. District Court for the Eastern District of Virginia, represents a significant disruption to cybercriminal activities. The operation involved a collaborative effort from multiple organizations, including Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, and The Shadowserver Foundation. These entities pooled their resources and expertise to dismantle the phishing infrastructure and mitigate its impact.

The EvilTokens service was specifically designed to compromise user inboxes, with Microsoft reporting that it had affected over 12,000 inboxes. The phishing kit offered by EvilTokens was allegedly sold on dark web forums, providing cybercriminals with the tools to conduct their attacks. The service's sophistication lay in its use of AI, which Microsoft stated was integrated into various aspects of the attack process. This AI integration likely enhanced the service's ability to create more convincing phishing lures, automate reconnaissance, and potentially evade detection mechanisms.

Microsoft's Digital Crimes Unit (DCU) led the investigation and takedown, working to disrupt the service's operations and prevent further harm. The EvilTokens phishing kit was reportedly sold on underground forums, enabling threat actors to launch targeted attacks. The service's capabilities included the use of device code, a method that can be employed to bypass multi-factor authentication (MFA) by tricking users into approving malicious login attempts. The AI-powered nature of EvilTokens suggests a growing trend of cybercriminals adopting advanced technologies to enhance the efficacy and scalability of their operations.

The takedown underscores the evolving threat landscape, where AI is increasingly being weaponized by malicious actors. Microsoft's statement highlighted that the EvilTokens service was designed to facilitate the theft of sensitive information, including credentials and financial data. The collaborative nature of the takedown, involving both private sector companies and cybersecurity organizations, demonstrates the importance of industry-wide cooperation in combating sophisticated cyber threats. The disruption of EvilTokens is expected to hinder the activities of numerous threat actors who relied on its services for their phishing campaigns.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next