Disrupting EvilTokens: The AI Chatbot Built for Cybercrime - Microsoft On the Issues

Compatibilidad
Ahorrar(0)
Compartir

| By Steven Masada, Associate General Counsel and General Manager, Microsoft’s Digital Crimes Unit

Microsoft has disrupted EvilTokens, a powerful cybercrime platform that used AI at every step of the attack chain—from compromising email accounts to designing intricate roadmaps for financial fraud and scams. While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed. The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action. 

In short, AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible.   

Within months of launching in February 2026, EvilTokens had been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, showing how quickly the service gained traction. Microsoft observed the highest concentrations of victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Affected organizations ranged from wholesale distribution and construction to financial services, real estate, higher education, and healthcare. Working with partners, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. In the United Kingdom, the Metropolitan Police Service’s cybercrime team arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens.  

But the significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works. 

From account access to financial fraud 

EvilTokens helped criminals gain access to email accounts by tricking victims into entering an authentication code on Microsoft’s legitimate sign-in page. By completing the normal authentication sign-in process, victims unknowingly gave criminals access to their email accounts without revealing their passwords. That access could persist even after a password reset if the associated sessions and tokens were not also revoked. Microsoft Threat Intelligence provides additional technical details about the operation, how device-code attacks work, and steps customers can take to protect themselves here. 

EvilTokens AI analysis of compromised inbox and suggested follow- up prompts.

Once inside an account, criminals have traditionally needed time and experience to sift through thousands of messages, identify decision-makers, understand payment processes, and find opportunities for fraud. 

EvilTokens began automating that work. Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization’s “money movers,” locate vendor invoices, and determine the best people to impersonate.

Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.

EvilTokens store on Telegram.
EvilTokens “Essential Tools” optimized for cybercrime.

AI lowered the barriers at both ends

Investigators found evidence that large portions of EvilTokens had been “vibe coded,” with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. 

The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

Disrupting the platform

No single organization could disrupt EvilTokens alone. The service relied on hosting providers, cloud services, AI tools, financial services, and other online resources that cybercriminals repurposed to support fraud at scale. 

The disruption combined civil legal action with coordinated operational work across industry and law enforcement. Because healthcare organizations were among those targeted, Health-ISAC—a global non–profit that helps health sector organizations share cyber threat information and collaborate to improve operational resilience—joined Microsoft’s legal action as a co-plaintiff.

With authorization from the U.S. District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to act against key parts of the platform. Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action.

The operation also demonstrated the value of rapid cooperation between private-sector investigators and law enforcement. Microsoft worked closely with specialist officers from the Metropolitan Police Service’s cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination. Both men have been released on police bail subject to conditions while the investigation continues. 

Seizure notice displayed after Microsoft and its partners disrupted infrastructure used by EvilTokens.

While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service. The case shows how AI is changing not only how cybercriminals operate, but also how defenders investigate and disrupt them. 

This action marks the Microsoft Digital Crimes Unit’s (DCU) 40th court-authorized disruption spanning nearly two decades of targeting cyber threat actors, malicious tools, and supporting infrastructure. It is also DCU’s first action against an end-to-end AI-enabled cybercrime service. 

What EvilTokens reveals about cybercrime’s next phase 

The infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it. As Microsoft notes in its 2026 Responsible AI Transparency Report, increasingly capable and accessible AI is being used to scale fraud, impersonation, and other forms of online abuse. EvilTokens offers an early example of how those capabilities can be combined with compromised accounts to accelerate financial fraud. 

For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days. Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.

https://blogs.microsoft.com/wp-content/uploads/sites/5/2026/09/FY27_OML_DCU-EvilTokens-Video_V4_092126_15mb.mp4

Detalles de contacto
sbaynes