A major AI-powered phishing service has lost access to its key infrastructure

Microsoft, other tech partners disrupted domains linked to EvilTokens.

A major AI-powered phishing service has lost access to its key infrastructure

TL;DR

  • Microsoft has taken down the infrastructure of EvilTokens, an AI-powered cybercrime platform.
  • EvilTokens used AI chatbots to analyze stolen corporate data and facilitate fraud.
  • The platform helped hackers compromise over 12,000 email inboxes in 10,000 organizations.
  • Microsoft seized 50 websites and disabled over 150 domains tied to EvilTokens' operations.
  • Two individuals were arrested in the UK in connection with the platform.
  • EvilTokens operated on a subscription model, charging hackers for access to its tools.
  • The AI tools condensed tasks that would normally take hackers days into hours.
  • Microsoft observed the highest victim activity in the U.S., Canada, UK, Australia, India, and France.
  • Coinbase traced approximately $1.1 million in revenue to the platform.
  • Evidence suggests EvilTokens itself was partially built using AI tools.