Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Microsoft took legal action this month against an AI-powered cybercriminal platform called EvilToke 2026-9-22 16:1:6 Author: therecord.media(查看原文) 阅读量:0 收藏

Microsoft took legal action this month against an AI-powered cybercriminal platform called EvilTokens, using court authorization to take the tool offline and work with police in the U.K. to arrest those allegedly behind it. 

Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud. 

Microsoft Digital Crimes Unit associate general counsel Steven Masada said they partnered with health sector cybersecurity non-profit Health-ISAC on a lawsuit in U.S. District Court that allowed them to dismantle the platform and related infrastructure. 

Microsoft also worked with officers within U.K.’s Metropolitan Police Service's cybercrime team, resulting in arrests of two men, aged 32 and 38, earlier this month. Microsoft declined to identify the men but said both have since been released on bail while police continue their investigation. 

“The two individuals were alleged operators of EvilTokens. We believe others may have supported the service in various capacities,” a spokesperson told Recorded Future News. 

A spokesperson for the Metropolitan Police Service confirmed that two men were arrested as part of an investigation into the online phishing service. Officers carried out warrants on two locations last Friday.

The Metropolitan Police Service said the two men were arrested on suspicion of making articles for use in fraud and money laundering offenses. Microsoft reported the issue to the Metropolitan Police Service in August, according to the spokesperson. 

"Phishing services bring misery to thousands, taking money from everyday people across the world,” said Detective Inspector Serena D'Adamo, whose team led the investigation. 

A Microsoft spokesperson said EvilTokens was unique because of how it automated disparate aspects of a cybercriminal’s workflow. 

“EvilTokens drew on capabilities from multiple AI models. As we note in our blog, OpenAI was an important partner in this disruption effort,” the Microsoft spokesperson said, declining to provide specifics on what other AI platforms were used to run EvilTokens. 

The platform was particularly alarming because it provided cybercriminals with intricate roadmaps for financial fraud and scams, combing through a victim’s email inbox and identifying ways they could be scammed or used to steal from others. 

The AI-style chatbot could help criminals “identify trusted relationships, payment authorizations and sensitive responsibilities, and other circumstances where fraud was most likely to succeed.”

“The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action,” Masada said. 

“In short, AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible.”

Masada added that EvilTokens launched in February 2026 and was linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide. The organizations attacked were concentrated in the U.S., Canada, U.K., Australia, India and France. 

The tech giant worked with dozens of companies to seize 50 websites that were used to operate the service and disabled 150 other additional domains tied to its infrastructure. 

‘Evil’ authentication codes

Victims were targeted with deceptive emails that used 44 different themes, ranging from invoices to file sharing requests. The emails typically contained malicious URLs, PDFs or other file types. 

The platform had dozens of pre-built phishing templates and landing pages with an AI-powered assistant to aid in structuring target-specific emails, according to a technical Microsoft examination of the site. 

Microsoft added that it used to take days or weeks for cybercriminals to go through a breached inbox and identify opportunities for fraud — but with EvilTokens the process was largely automated within minutes. 

“Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, identify trusted relationships, and recommend potential targets,” Masada explained. “Preset prompts offered to find wire-transfer discussions, identify the organization’s ‘money movers,’ locate vendor invoices, and determine the best people to impersonate.”

One of the most widely used features in EvilTokens was the device code phishing flow, which took advantage of security gaps in devices that cannot support standard sign-in methods like smart TVs, printers, conferencing tools and Teams devices. 

Victims are sent a short code on the device they are trying to sign in from and are told to enter that code into a browser on a separate device to complete authentication. But instead of a legitimate device requesting access, the threat actor initiates the flow and provides the user with a code through a phishing lure. When the code is entered, victims unknowingly authorize the cybercriminals’ session and grant them access without ever handing over their password. 

Victims unknowingly handed over full access to their email accounts without providing their passwords and the access could even persist if passwords were changed.

Investigators found that EvilTokens was largely “vibe coded” — a term used to describe platforms or websites built largely through leveraging large language models. The platform had customer support, management dashboards and tools to automate significant parts of the financial exploitation process. 

EvilTokens also relied on a web of hosting providers, cloud services, AI tools and other resources to operate. Microsoft worked with Cloudflare, Coinbase, The Shadowserver Foundation, TRM Labs and more to take the site down. 

Microsoft officials said the case revealed that AI-enabled fraud has rapidly advanced from simply creating realistic phishing emails to now automating and personalizing nearly every aspect of a cybercriminal’s actions. 

The takedown is the 40th court-authorized disruption launched by Microsoft Digital Crimes Unit and the organization’s first against what they call an “end-to-end AI-enabled cybercrime service.”

In June, Microsoft dismantled hundreds of servers and domains tied to cybercrime-as-a-service infrastructure belonging to cybercriminal gangs distributing SocGholish, Amadey and StealC malware. The company previously targeted other popular cybercriminal platforms like RaccoonO365 and RedVDS over the last year.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
如有侵权请联系:admin#unsafe.sh