BLOCKCHAIN AI.NEWS

AI × Crypto

EvilTokens Sold a Chatbot That Picked Who to Impersonate

Microsoft and eight partners pulled down a phishing service tied to more than 12,000 compromised inboxes across 10,000 organizations. Coinbase traced the platform's entire revenue — about $1.1 million — to four Tron addresses. The thirteen FBI complaints Microsoft could link to it report more in losses than the business ever earned.

Editorial illustration: a chrome robotic arm draws one warmly lit envelope forward out of a grid of identical cold steel envelopes
✓ Disruption announced Sep 22 by Microsoft's Digital Crimes Unit · Technical analysis from Microsoft Security · Court filing and partner detail reported by CyberScoop · Pricing tiers and victim telemetry from The Hacker News · Arrest detail from BleepingComputer · On-chain tracing by Coinbase and TRM Labs · Additional reporting by Fortune

The interesting thing about EvilTokens is not that it phished people. Phishing kits are a commodity, and have been for a decade. The interesting thing is what the operators bolted onto the back end: once a mailbox was open, a chatbot read it and told the buyer whose name to forge.

Microsoft's Digital Crimes Unit announced on Monday that it and eight outside organizations had taken apart the platform's infrastructure. Working as co-plaintiff with Health-ISAC, Microsoft obtained a civil order from the U.S. District Court for the Eastern District of Virginia, seizing 50 websites and disabling more than 150 further domains, according to its own account. Several outlets, including CyberScoop and Fortune, put the domain figure at 175 or more; Microsoft's published number is the lower one.

The service launched on a Telegram storefront in February 2026. Within months Microsoft ties it to more than 12,000 compromised inboxes across over 10,000 organizations, concentrated in the United States, Canada, the United Kingdom, Australia, India and France, and weighted toward wholesale distribution, construction, financial services, real estate, higher education and healthcare. Microsoft tracks the operators as Storm-2992 and says the group is not affiliated with any other cybercrime crew it follows.

The part that isn't new

The access technique is device code phishing, and it is old enough to have its own Microsoft advisory from February 2025. It works by abusing a legitimate OAuth flow designed for devices that cannot show a login form — a TV, a printer, a command-line tool.

Per Microsoft's technical write-up, the attacker starts the flow rather than the victim. A lure — the kit shipped 44 themes, including invoices, requests for proposals, shared files and password-expiry notices — sends the target to a page that quietly asks Microsoft's identity service for a live device code. The page shows the victim that code and a button to continue. The victim then types the code into Microsoft's own portal at the real microsoft.com address, signs in normally, and approves what the screen describes as a pending device.

Nothing about that sequence requires the victim's password to pass through attacker hands, which is precisely why multi-factor authentication does not stop it. The user authenticates genuinely; the session they authorize is someone else's. Microsoft's explanation is that because authentication completes on a separate device, the requesting session is never strongly bound to the user's actual context. What the attacker collects at the far end is an access token, a refresh token, and in some cases a Primary Refresh Token good for registering a device and holding on.

That last detail deserves a moment from anyone running an incident response playbook. Microsoft notes that standard session revocation typically kills refresh tokens while leaving already-issued access tokens valid for up to an hour. Resetting the password is not containment. The company's own guidance is to revoke sign-in sessions through the Graph API, force re-authentication with Conditional Access, and temporarily disable the account outright.

The hosting was similarly unremarkable and similarly effective: pages ran on Vercel, Cloudflare Workers and AWS Lambda, so the traffic looked like ordinary enterprise cloud traffic and domain blocklists had nothing distinctive to catch.

The part that is

After the mailbox opened, EvilTokens offered an assistant. Microsoft describes a chatbot that reads the compromised inbox, maps who in the organization holds payment authority, identifies trusted relationships, finds the threads where wire transfers get discussed, and recommends both the target and the person worth impersonating. It then drafts the business email compromise message in context. Microsoft says it worked across more than 20 languages, and used Microsoft Graph queries to sketch the organization's structure and permissions on its own.

Steven Masada, who leads the Digital Crimes Unit as associate general counsel, framed the distinction plainly in remarks reported by CyberScoop: the AI was not merely writing better prose. "It helped them decide who to target, who to impersonate," he said.

That is the labor that used to separate a competent business email compromise crew from an incompetent one. Reading a stranger's mailbox in a language you may not speak, working out that the controller signs off on payments over a threshold and the facilities manager does not, then writing in the register of a specific colleague — that is hours of careful work per victim, and it does not scale. Packaged as a subscription feature, it does.

What it cost to rent

The pricing, as itemized by The Hacker News, was ordinary software-business pricing.

The EvilTokens price list

ComponentPriceTerms
Office 365 Capture Link$1,500one-time, lifetime panel access
Phishing page code + API$500per month
SMTP Sender$1,000one-time
B2B Sender$600one-time
Source: The Hacker News, Sep 22, 2026, reporting the storefront tiers advertised on Telegram. Microsoft's own posts cite the $1,500 entry fee and $500 recurring subscription without itemizing the sender modules.

Trevor Hilligoss, SpyCloud's chief intelligence officer, described the platform as using AI to make the hard parts easy. SpyCloud recovered 8,708 unique victim accounts spanning 6,585 corporate email domains across 79 countries, and shared them with Microsoft.

Four addresses on Tron

The crypto side of this is smaller than the headline numbers suggest, and that is the point worth sitting with.

Coinbase's threat researchers traced the platform's revenue to four addresses on Tron: roughly $1.1 million in total, arriving in more than 1,000 separate deposits from more than 700 distinct addresses. TRM Labs, which also worked the case, says it mapped the surrounding activity and followed funds toward downstream cash-out points, though its public post names no exchanges, wallets or amounts.

Set that $1.1 million against the damage. Microsoft says it correlated at least thirteen complaints filed with the FBI's Internet Crime Complaint Center to EvilTokens activity, representing about $1.7 million in reported losses. Thirteen complaints. The platform compromised twelve thousand mailboxes. Whatever the real total is, the thirteen reports Microsoft could match already exceed everything the operators collected in subscription fees.

One detail in the public record does not line up cleanly, and it is worth flagging rather than explaining away. Coinbase's tracing window is given as October 2025 through June 2026, but the service is dated to a February 2026 launch. That leaves roughly four months of payments to those addresses predating the product they supposedly bought. It may be that the operators ran an earlier service, or that the wallets were reused, or that the window is simply the search range rather than the range of activity found. Coinbase's own write-up is behind a block for this desk's requests, and neither Microsoft's posts nor the outlets covering them address the gap. We do not know, and nobody has said.

Two arrests, no charges

Specialist officers from the Metropolitan Police Service's cybercrime team, acting on intelligence Microsoft shared, arrested two men aged 32 and 38 in the greater London area and seized their devices. Microsoft dates the arrests to September 11, 2026; CyberScoop puts them a week later, on September 18. Both men were released on police bail while the investigation continues, on suspicion of making articles for use in fraud and of money laundering. Detective Inspector Serena D'Adamo said the Met remains committed to holding to account those who enable crime, per BleepingComputer.

Microsoft's civil complaint names two individuals as defendants, according to CyberScoop's reading of the filing. Microsoft's own public posts do not name them, the Met has not identified the men it arrested, and no one has been criminally charged. Allegations in a civil complaint are untested. For those reasons this desk is not printing the names.

The disruption is also not a shutdown, a point BleepingComputer makes and Microsoft does not contradict: partners seized active infrastructure, but that is a different operation from dismantling the group. Fortune reports the operators were already building successors aimed at Okta and Gmail accounts.

The partner list is its own small story about where this work now happens. Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs each moved against a different layer — delivery, payments, model access, hosting, credential exposure, scanning, the blockchain trail. Health-ISAC went to court alongside Microsoft; a police force made the arrests. Two of the nine organizations that acted against a business email compromise platform are crypto companies, which tells you where the subscriptions were settling.

The Take

Strip out the AI and this is a competent takedown of a mid-sized criminal SaaS business — worth reporting, not worth alarm. The AI is what changes the shape. Device code phishing has been documented since early 2025 and the mitigation has not moved: block the device code flow in Conditional Access where you can, require phishing-resistant authentication, and remember that revoking a session leaves access tokens breathing for another hour. That is the uncomfortable part — twelve thousand inboxes fell to a technique with an eighteen-month-old public advisory. What the chatbot removed was the last bottleneck. Mailbox reconnaissance is what kept business email compromise artisanal: it needed someone who could read the thread, infer the org chart, and pick the one name that would not raise an eyebrow. At $500 a month that person is a feature. The question for a security team is no longer whether staff can spot a badly written invoice email. It is what a patient reader would learn from an hour inside your finance inbox — because that reader is no longer scarce, and no longer expensive.

More on the subject