Microsoft lands its first takedown of a fully AI-run crime service

Microsoft has seized the infrastructure behind a phishing kit that used AI to pick its victims, and two suspects are on bail in London.

CSBadmin
2 Min Read

Microsoft’s Digital Crimes Unit has seized 50 websites tied to EvilTokens, a phishing-as-a-service kit that let low-skilled criminals compromise more than 12,000 inboxes at over 10,000 organizations.

The platform appeared in February 2026 and rented for $1,500 upfront plus $500 a month. Its specialty was device code phishing: rather than stealing a password, it tricks a victim into entering an attacker-supplied code on Microsoft’s real sign-in page. The victim’s own multifactor prompt never fires, because the session being approved belongs to the intruder.

What set EvilTokens apart was where AI sat in the chain. A chatbot read the contents of a compromised mailbox, worked out who controlled payments, chose which colleagues to impersonate and drafted the follow-up email. Microsoft says the service itself was likely coded with AI. The kit shipped 44 lure themes.

London’s Metropolitan Police arrested two men, aged 32 and 38, on September 18; both are on bail. Microsoft named suspects in a US complaint that also targets five unnamed individuals.

Coinbase followed the money instead of the malware, tracing about $1.1M in revenue through Tron addresses, a thread that helped identify an operator. Health-ISAC joined as a co-plaintiff, with Cloudflare, OpenAI, Railway, SpyCloud, Shadowserver and TRM Labs contributing.

Microsoft’s Steven Masada warned that the model outlives the platform: once a mailbox falls, criminals grasp its contents in minutes, not days. Independently verify any request to change payment details or move funds through a second channel.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.