Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Summary

Microsoft has announced the takedown of the EvilTokens device code phishing service, which utilized AI throughout its attack chain. This operation, authorized by a U.S. federal court, was conducted with the assistance of several industry partners, including Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, and SpyCloud. The service was linked to the compromise of approximately 12,000 inboxes.

IFF Assessment

FOE

The takedown of a sophisticated AI-powered phishing service represents a significant disruption to a threat actor, but the existence and capabilities of such a service are a concern for defenders.

Defender Context

This incident highlights the growing sophistication of phishing attacks, particularly the integration of AI to automate and enhance various stages of the attack chain. Defenders should be aware of AI-assisted tactics, such as automated reconnaissance and credential harvesting, and ensure their security controls and user awareness training are updated to counter these advanced methods.

Read Full Story →