Article
AI News Cybersecurity Microsoft coinbase disrupt eviltokens

Microsoft and Coinbase break up AI-powered phishing operation

Takedown of the EvilTokens "phishing-as-a-service" kit leads to two arrests and the seizure of dozens of websites.

by TechDefused Newsroom
The image features a close-up view of cryptocurrency tokens with the Tether symbol prominently displayed. The tokens are shown alongside a device that appears to be a cryptocurrency wallet, illuminated by green lights. — Credit: Photo by DrawKit Illustrations / Unsplash cPhoto by DrawKit Illustrations / Unsplash
Photo by DrawKit Illustrations / Unsplash

Microsoft and Coinbase have disrupted EvilTokens, a cyber-fraud operation that used artificial intelligence (AI) to target corporate email, in a takedown that led to two arrests and legal action, the companies said.

Coinbase, the San Francisco-based cryptocurrency exchange, and Microsoft, the software group behind Windows and Office, described EvilTokens as a ready-made phishing kit sold on the messaging app Telegram.

The kit included an AI-powered analyst that mapped trusted relationships within a target company, identified who controlled payments and shaped highly targeted invoice scams, and investigators traced about $1.1 million in subscriber payments.

The Metropolitan Police arrested two men, aged 32 and 38, on suspicion of fraud and released them on bail.

Microsoft's civil action, meanwhile, led to the seizure of 50 websites and the disabling of more than 175 domains linked to the operation.

"It completely obliterates the barrier to entry on phishing as a service, and can be operated on an industrial scale," said Charlotte Surrey of Coinbase's global intelligence team.

EvilTokens abused Microsoft's sign-in system by showing codes on fake pages that victims were told to enter on genuine sites, a trick that let the operators bypass two-factor authentication, the security check that asks for a second code as well as a password, and stay in accounts even after passwords were reset.

The companies said the takedown had grown into a coalition that also included Cloudflare and OpenAI, and that the operators had been building tools to target Okta and Gmail, as the cross-border investigation continues.

by TechDefused Newsroom