News: 0185744966

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform (thehackernews.com)

(Wednesday September 23, 2026 @03:04AM (EditorDavid) from the gone-phishing dept.)


Microsoft's security blog describes the fight against a new " [1]AI-powered cybercrime platform " offering phishing-as-a-service, with AI-tailored lures and analyses of compromised inboxes (to identify high-value targets). The site compromised more than 12,000 inboxes in over 10,000 organizations around the world, compromising business accounts "at scale" with automated attacks and prebuilt phishing templates. AI tools could even sift through a victim's mailbox to help engineer better phishing messages.

To disrupt EvilTokens Microsoft worked with other organizations, including Cloudflare, [2]Coinbase , [3]OpenAI , [4]Railway , [5]SpyCloud , [6]Shadowserver Foundation , and [7]TRM Labs to [8]Health-ISAC (a non-profit helping health sector organizations share cyber threat information).

"Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time," security company SpyCloud [9]told The Hacker News .

From [10]Microsoft's security blog :

> Microsoft also notified affected customers, helped remediate compromised accounts, and shared intelligence to support further defensive and investigative action... Microsoft worked closely with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled officers to take operational action in the United Kingdom. On September 11, 2026, officers arrested two men, aged 32 and 38, and seized digital devices and other items for examination... While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service...

>

> Campaigns leveraging EvilTokens have impacted organizations in various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with the highest concentrations of observed victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Working with partners, Microsoft's Digital Crimes Unit (DCU) facilitated a [11]coordinated disruption of infrastructure used to operate the EvilTokens service .

Sometimes stolen tokens were used to give new devices access to a victim's inbox. (A code authenticating the new device was sent to the targeted user, who unknowingly authorize the threat actor's session and grants access to their account...) But "AI was not simply helping attackers write more convincing messages," says [12]another Microsoft blog post . "It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible."

> The significance of EvilTokens extends beyond its rapid growth and global reach. It offers an early warning of what happens when cybercriminals combine stolen access with AI capable of understanding how an organization works... Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets. Preset prompts offered to find wire-transfer discussions, identify the organization's "money movers," locate vendor invoices, and determine the best people to impersonate. Sold through Telegram for a $1,500 initiation fee and a recurring $500 subscription, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service. Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface.

>

> Investigators found evidence that large portions of EvilTokens had been "vibe coded," with AI helping its creators build the platform itself. They also determined that EvilTokens drew on capabilities from multiple AI models. The result was more than a collection of attack tools. EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.



[1] https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/

[2] http://www.coinbase.com/blog/taking-down-evil-tokens

[3] https://openai.com/

[4] https://railway.com/

[5] http://www.spycloud.com/blog/disrupting-the-eviltokens-phaas-platform/

[6] https://www.shadowserver.org/

[7] https://www.trmlabs.com/resources/blog/trm-labs-supports-microsofts-disruption-of-eviltokens-an-ai-powered-cybercrime-service

[8] https://health-isac.org/

[9] https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html

[10] https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/

[11] https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/

[12] https://blogs.microsoft.com/on-the-issues/2026/09/22/disrupting-eviltokens-the-ai-chatbot-built-for-cybercrime/



Um ... (Score:3)

by fahrbot-bot ( 874524 )

> AI-Powered

I think you mean, [1]SI-Powered [slashdot.org] /s (*heavy-sigh*)

[1] https://politics.slashdot.org/story/26/09/22/2258253/trump-denounces-attempts-to-control-ai-wants-it-renamed-super-intelligence-in-us-documents

uh (Score:3)

by drinkypoo ( 153816 )

Microsoft is an Automated, AI-Powered Phishing-as-a-Service Platform. [1]The service is provided to the US Government [wikipedia.org].

[1] https://en.wikipedia.org/wiki/PRISM#Companies

Re: (Score:2)

by Required Snark ( 1702878 )

Microsoft updates will be discontinued?

That's the only way I can read this that makes any sense IRL. Obviously wishful thinking.

Jargon Coiner (#4)

An irregular feature that aims to give you advance warning of new jargon
that we've just made up.

* FREE LECTURE: Attempting to explain the concepts of Linux, Open Source
software, free software, and gift cultures to someone who is not
familiar with them. Made extra difficult if the explainee has been
misled by superficial mainstream news articles about the subject.

Example: "Eric gave an hour-long free lecture to his mother-in-law after
she asked him about this Linux thingy she read about in USA Today."

* LEXICON LAZINESS: Filling a fortune file with a list of fake jargon
instead of publishing something more substantive (and funny) that would
take more effort to write.

* FOR(;;)TUNE LOOP: Repeatedly running fortune(6) for cheap entertainment.

Example: "During a coffee break, Bob became bored and started a
for(;;)tune loop. His boss had to issue a SIGTERM to get him to resume
working."