Microsoft announced on Tuesday that it led an industry-wide disruption of a subscription-based scam platform named EvilTokens, which utilized an AI chatbot to compromise approximately 12,000 Microsoft accounts over a span of a few months.
What Happened
According to Microsoft, EvilTokens was introduced via a Telegram channel in February and operated on a subscription model, charging customers an initial fee of $1,500 followed by a recurring charge of $500 per month. The platform provided a streamlined service for cybercriminals to compromise email accounts in large numbers. Once access was gained, the tool helped users analyze inboxes, select high-value targets, and draft follow-up emails designed to trick company employees into transferring funds to attacker-controlled accounts.
At the core of the service was an AI-style chatbot capable of analyzing a victim's inbox to identify trusted relationships, payment authorizations, and sensitive responsibilities. Microsoft stated that the platform could recommend fraud strategies and draft messages impersonating trusted contacts, enabling criminals to execute scams more effectively. Microsoft noted that this AI-assisted approach reduced the time required to compromise accounts and plan fraud from days to minutes.
Why It Matters
The disruption highlights the increasing integration of artificial intelligence into cybercrime-as-a-service models. By automating the analysis of victim data and the generation of convincing social engineering lures, platforms like EvilTokens lower the barrier to entry for less-skilled criminals while increasing the speed and scale of attacks. The subscription pricing structure suggests a commoditization of AI-driven fraud tools, allowing attackers to access sophisticated capabilities for a fixed monthly cost. This trend poses challenges for security vendors and enterprises, as AI-generated communications can be harder to distinguish from legitimate correspondence, potentially increasing the success rate of business email compromise attacks.
The Bottom Line
Microsoft's action against EvilTokens demonstrates a proactive approach to disrupting AI-enhanced criminal infrastructure. The case serves as a reminder that generative AI is being rapidly adopted in the underground economy to automate and scale traditional phishing and fraud techniques, requiring defensive strategies that account for machine-generated social engineering at volume.