Microsoft dismantles AI-powered phishing platform EvilTokens

1 day ago 3



Phishing has been a problem for decades. What’s new is that it now comes with a subscription tier and an AI content generator, and the people running it were apparently operating out of the UK until last week. Microsoft’s Digital Crimes Unit announced on September 22 that it had dismantled the core infrastructure behind EvilTokens, a phishing-as-a-service platform the company tracks internally as Storm-2992. The operation compromised more than 12,000 Microsoft 365 inboxes across over 10,000 organizations globally before Microsoft and its partners shut it down. Two UK administrators, aged 32 and 38, were arrested in coordination with Health-ISAC, cybersecurity firm SpyCloud, and local law enforcement. Both suspects were subsequently released on bail while investigations continue. How EvilTokens actually worked The clever part of EvilTokens was that it didn’t try to trick victims into handing over passwords. It exploited Microsoft’s own device authorization grant flow, the legitimate OAuth process that lets users authenticate on devices without keyboards, like smart TVs. A victim would receive a phishing message directing them to a real Microsoft page and asking them to enter a devic...

Read Entire Article