EvilTokens, introduced via a Telegram channel in February, charged an initial $1,500 fee and $500 per month thereafter, offering a streamlined service for compromising email accounts at scale. According to Microsoft, the platform not only helped attackers access inboxes but also deployed an AI-style chatbot to analyze victims' communications, identify trusted relationships, payment authorizations, and sensitive responsibilities, and recommend fraud strategies.
“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said in a blog post. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”
The disruption, which involved collaboration across the cybersecurity industry, represents a focused effort to dismantle a new breed of crime-as-a-service that leverages generative AI to reduce the time required for account compromise from days to minutes. Microsoft did not disclose the full list of partners involved or the specific technical steps taken to disrupt EvilTokens, but the company emphasized that the takedown was the result of coordinated legal and technical actions.
The 12,000 compromised accounts highlight the growing threat of AI tools being weaponized by cybercriminals, where even relatively low-cost subscriptions can enable large-scale attacks on individuals and organizations.