Microsoft Disrupts AI-Powered Phishing Platform EvilTokens, Cybersecurity Threat

www.news4hackers.com-microsoft-disrupts-ai-powered-phishing-platform-eviltokens-cybersecurity-threat-microsoft-disrupts-ai-powered-phishing-platform-eviltokens-cybersecurity-threat

Microsoft disclosed on Tuesday the disruption of EvilTokens, an AI-driven phishing operation that targeted organizations globally.

Overview of EvilTokens

The platform, which emerged in February 2026, was responsible for compromising over 12,000 accounts across more than 10,000 organizations in regions including the United States, Canada, the United Kingdom, Australia, India, and France.

AI-Driven Attack Techniques

EvilTokens leveraged device code phishing, a method that exploits the authentication process designed for devices lacking traditional login capabilities, such as smart TVs and printers. This technique involves prompting users to enter a verification code displayed on the device into a web browser on another device. Attackers manipulated this flow by tricking users into inputting maliciously generated codes, granting unauthorized access to accounts without requiring passwords.

Microsoft highlighted that the AI component enabled threat actors to prioritize targets, simulate impersonation, and optimize exploitation strategies to maximize financial gain.

Subscription Model and Takedown Efforts

The platform operated as a subscription-based service, with initial access priced at $1,500 and a recurring $500 monthly fee. Microsoft’s takedown effort involved seizing 50 websites hosting the platform and disabling over 150 domains linked to its infrastructure. The operation also led to the arrest of two individuals, Felix Utomi and Waidi Segun Adams, in the United Kingdom.

Microsoft filed a legal complaint naming the suspects and targeting five unnamed co-conspirators.

Collaboration and Impact

Collaboration with entities such as SpyCloud, TRM Labs, Coinbase, Health-ISAC, Cloudflare, OpenAI, Railway, and The Shadowserver Foundation contributed to the disruption. The action marks a significant setback for cybercriminals utilizing AI to automate and scale phishing campaigns.

Recommendations for Organizations

The incident underscores the growing sophistication of AI-powered cyber threats and the necessity for advanced detection and mitigation strategies. Organizations are advised to reinforce authentication protocols, monitor for anomalous activity, and educate users on recognizing phishing attempts.



About Author

en_USEnglish