Microsoft and Coinbase probe leads to arrest of crooks behind ‘EvilTokens’, a DIY phishing network powered by AI
We’ve all seen the emails: A spoofed message from your company’s CFO or a vendor asking you to pay an outstanding invoice.
These phishing messages lead to millions of dollars of fraudulent payments every year, and are becoming more realistic all the time.
The good news is companies are fighting back: On Tuesday, Microsoft and Coinbase announced they had taken down a phishing network, known as EvilTokens, that has defrauded businesses ranging from real estate firms to banks to healthcare providers.
In a blog post describing the scam, the companies explained that EvilTokens sold a do-it-yourself phishing kit over Telegram designed to exploit Microsoft Outlook email accounts.
The kit came with a sinister feature, described by the post as “an AI-powered analyst that mapped trusted relationships, identified who controlled payments, and flagged where fraud was most likely to succeed.” This meant that, once a victim fell for a phishing email, scammers could use the AI analyst to create especially persuasive emails to target those in position to pay.
This is a notable evolution from conventional phishing campaigns, which have typically relied on a “spray and pray” approach to luring victims.
The EvilTokens tool also proved hard to dislodge.
As the blog post explained, the phishing campaigns included links directing victims to fake Microsoft or DocuSign pages that displayed a code, and instructed them to enter it on a legitimate Microsoft website to verify their identity.
If they did so, EvilTokens was able to bypass two-factor authentication and stay hidden on their computers—even surviving password resets.
The software powering the EvilTokens kit represents a sophisticated evolution of conventional phishing tools but, according to Coinbase’s security team, the most alarming attribute is that it requires few technical skills to use it.
“It completely obliterates the barrier to entry on phishing as a service, and can be operated on an industrial scale,” said Charlotte Surrey, an investigator on Coinbase’s global intelligence team.
She added that the EvilTokens kit sold on Telegram for between $100 and $300 per month, and came with features that let anyone vibe code a customized attack.
The takedown The EvilTokens investigation came in the course of an ongoing partnership between security teams at Coinbase and Microsoft, which regularly swap intelligence on cyber threats.
The companies spent months uncovering who was behind the Telegram campaign, and then shared their findings with law enforcement.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on fortune.com — the content belongs to Fortune.