Microsoft disrupts EvilTokens, an AI chatbot built for email fraud
Microsoft said it disrupted EvilTokens, a phishing-as-a-service platform sold on Telegram that used an AI-style chatbot to analyze compromised Microsoft 365 inboxes, rank money movers, and draft impersonation mail — the Digital Crimes Unit’s first court-authorized action against an end-to-end AI-enabled cybercrime service.
SECURITY desk — MFA-resistant token theft plus inbox-reading AI turns BEC from a skilled craft into a $500/month product; defenders must assume a stolen inbox can be mapped in minutes.
What Microsoft says it took down. EvilTokens was a cybercrime platform sold so other people could run the fraud. The security blog calls that model phishing-as-a-service. Phishing is a fake message meant to trick someone into handing over access. As-a-service means the seller runs the kit and the buyer pays to use it. Microsoft says the platform used AI from the takeover of an email account through the plan for the fraud. At the center was an AI-style chatbot. It read a victim’s inbox. It picked out trusted relationships, payment approvals, and people whose jobs made a fraud more likely to work. It recommended a strategy, including a draft that pretended to be someone the victim already trusted. Microsoft’s point: the AI was not only writing smoother emails. It was choosing who to target, who to impersonate, and how to pull the most money out of that relationship. AI, here, means software that reads the mail and proposes the next move. A chatbot is the window the buyer typed into. File those sentences as the On the Issues post’s. This desk did not open a stolen inbox.
What the prompts offered, once the mailbox was open. A person used to need time to read thousands of messages, find who can send money, and spot a fraud. Microsoft says EvilTokens automated that work. The tools could summarize and translate mail, surface conversations about money, map who holds which job, name trusted relationships, and recommend targets. Preset prompts offered to find wire-transfer threads, identify the organization’s “money movers,” locate vendor invoices, and pick the best people to impersonate. A wire transfer is a bank payment. A money mover, in that phrase, is someone who can send or approve one. A vendor invoice is a bill from a supplier. File the prompt list as Microsoft’s. This desk did not click one.
How the access was taken, in plain words. The path was device-code phishing. A device code is a real Microsoft sign-in made for a gadget that cannot show a normal login, such as a smart TV or a printer. The person gets a short code and types it on Microsoft’s own sign-in page. EvilTokens tricked people into doing that for the attacker’s session. Finishing the normal sign-in handed over the mailbox without the person giving up their password. Microsoft says that access could last after a password change if the sessions and tokens were not also revoked. A token, here, is the pass the sign-in creates so the mailbox stays open. A session is that signed-in stretch. Revoke means cancel those passes, not only change the password. Multifactor authentication, shortened to MFA, is a second proof besides the password. The security blog says this kind of token theft became common as companies turned MFA on, because the code is typed on the real Microsoft page. File that description as Microsoft’s. This filing does not print the kit’s steps.
How far it spread, and whose counts they are. Within months of a February 2026 launch, Microsoft linked EvilTokens to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide. More than 12,000 is the mailbox count. More than 10,000 is the organization count. They are not the same number. The highest concentrations Microsoft observed were in the United States, Canada, the United Kingdom, Australia, India, and France. The organizations it names ran from wholesale distribution and construction to financial services, real estate, higher education, and healthcare. Both posts print that scale and that list. This desk did not count the inboxes.
What a buyer paid. The On the Issues post says EvilTokens was sold on Telegram for a $1,500 initiation fee and a $500 monthly subscription. Telegram is the chat app where Microsoft says the kit was advertised and supported. $1,500 is the price to start. $500 is the monthly fee. The security blog prints the same prices in U.S. dollars. It also says extra tools had their own 30-day fees. This filing does not turn that price list into a shopping guide. The On the Issues post says the subscription put account takeover, mailbox analysis, target picking, and fraud preparation in one service. Work that used to take skill in identity attacks, cloud systems, social engineering, and financial fraud was a ready-made screen. Social engineering, here, means tricking a person. Microsoft also says investigators found evidence that large portions of the platform had been “vibe coded,” with AI helping its creators build the service, and that the platform drew on more than one AI model. The page does not name those models. Do not add them. OpenAI is named later as a partner in the disruption. That is not a claim that an OpenAI model ran inside the kit. File the prices and the vibe-coded sentence as Microsoft’s.
Who joined the disruption, and what Microsoft says was seized. Microsoft says no single organization could do it alone. Because healthcare groups were among the targets, Health-ISAC joined the legal action as a co-plaintiff. Health-ISAC is a nonprofit where health organizations share information about cyber threats. With authorization from the U.S. District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to act against key parts of the platform. The page names those partners. It does not say what each one did. Do not assign a job the page left blank. Working with partners, Microsoft seized 50 websites used to run the service and disabled more than 150 other domains tied to the infrastructure. A domain is a web name. Fifty is the count of sites seized. More than 150 is the count of other names disabled. Microsoft also says it notified affected customers, helped fix compromised accounts, and shared intelligence for further defense and investigation. File the court, the partner list, and those counts as the On the Issues post’s. This desk did not read the court order, and the page does not print a case number. Do not add one.
The arrests, as the police action Microsoft describes. Microsoft says it worked with specialist officers from the Metropolitan Police Service’s cybercrime team in the United Kingdom. On 11 Sep 2026 those officers arrested two men, ages 32 and 38, on suspicion of offenses connected with the alleged operation, and seized digital devices and other items for examination. Both were released on police bail with conditions while the investigation continues. Suspicion, alleged, and bail are the post’s words. An arrest is not a conviction. The security blog’s name for the actor who developed and supported the kit is Storm-2992. That is a tracking name. The On the Issues post does not say the two men are Storm-2992. Do not merge them. This desk did not attend the arrest.
Where this sits in Microsoft’s own count. The On the Issues post says this is the Digital Crimes Unit’s 40th court-authorized disruption, across nearly two decades of cases against threat actors, malicious tools, and the infrastructure that supports them. It is also the unit’s first action against an end-to-end AI-enabled cybercrime service. End-to-end, here, means the service covered the path from stolen access to a prepared fraud, not one isolated trick. The Digital Crimes Unit, shortened to DCU, is the Microsoft team that brought the case. 40th and first are Microsoft’s words. This desk did not audit the prior 39.
What Microsoft says a defender should assume. The infrastructure was disrupted. Microsoft says the model will not vanish with it. The lesson on the page: once an inbox is compromised, criminals may understand its contents in minutes, not days. Identity protections still matter. A company should also check, on a separate trusted channel, any request to change payment details, redirect funds, or approve an unusual transaction. The security blog calls the fraud business email compromise, shortened to BEC: a message that looks like it came from someone trusted, aimed at moving money. The same blog says Microsoft recommends blocking device-code sign-in wherever a company does not need it. Minutes not days is Microsoft’s warning. It is not a stopwatch this desk ran. The security blog also publishes detection names and hunting queries. This filing does not reprint them.
Plain English for the rest of the card: phishing-as-a-service = a kit a criminal sells so someone else can send the phishing. chatbot = the window the buyer used to ask the stolen inbox questions. device code = a short code typed on Microsoft’s real sign-in page, meant for gadgets that cannot show a normal login. token = the pass that keeps the mailbox open after sign-in. session = that signed-in stretch. revoke = cancel the pass, not only change the password. MFA = multifactor authentication, a second proof besides the password. money mover = someone who can send or approve a payment. wire transfer = a bank payment. Telegram = the chat app where Microsoft says the kit was sold. $1,500 = the fee to start. $500 = the monthly fee. Health-ISAC = the health-sector group that joined the case. domain = a web name. 50 = websites seized. more than 150 = other domains disabled. more than 12,000 = inboxes. more than 10,000 = organizations. Storm-2992 = Microsoft’s tracking name for the kit’s developer and support actor, not a name this desk tied to the two arrests. DCU = Microsoft’s Digital Crimes Unit. 40th = Microsoft’s count of court-authorized disruptions. BEC = business email compromise, fraud that impersonates a trusted person to move money. This filing is the 22 Sep disruption.
PRIMARY here: Microsoft’s 22 Sep 2026 On the Issues post, “Disrupting EvilTokens: The AI Chatbot Built for Cybercrime,” by Steven Masada — Tier A PRIMARY, the company’s own record — and the same-day Microsoft Security Blog post, “Unmasking EvilTokens: Getting to the root of device code phishing,” by Microsoft Threat Intelligence — Tier A PRIMARY, the technical account. Neither page printed an hour. The disruption, the chatbot’s inbox analysis, the money-mover prompts, the device-code description, the more-than-12,000 inboxes and more-than-10,000 organizations, the six countries, the industry list, the February 2026 launch, the $1,500 and $500 prices, the vibe-coded sentence with no model names, Health-ISAC as co-plaintiff, the Eastern District of Virginia authorization, the partner list with no per-partner job, the 50 websites and more than 150 domains, the customer notifications, the 11 Sep arrests of two men ages 32 and 38 on suspicion, the bail, the 40th disruption, and the first end-to-end AI-enabled cybercrime action are the On the Issues post’s. Storm-2992, the phishing-as-a-service label, the MFA context, the BEC label, and the recommendation to block device-code sign-in where it is not needed are the security blog’s. The scale, the countries, and the industries appear on both. NOT claimed: that this desk seized a server, opened an inbox, counted the 12,000 or the 10,000, named the AI models inside the kit, treated OpenAI’s role as a partner as proof those models ran the chatbot, read a case number, assigned a task to Cloudflare, Coinbase, Railway, SpyCloud, Shadowserver, or TRM Labs beyond the page’s “worked with,” merged Storm-2992 with the two arrested men, treated the arrest as a conviction, audited the prior 39 disruptions, reprinted a hunting query, named a victim company from the panel screenshot, treated a dollar figure on that panel as a measured loss, a stock tip, or investment advice. Distinct from the already-filed salt-security-aidr, outerlimit-16m, and proofpoint-agentic-dai.
RELATED
On 22 Sep 2026, Microsoft said it disrupted EvilTokens. The public record is Steven Masada’s On the Issues post, “Disrupting EvilTokens: The AI Chatbot Built for Cybercrime.” Masada is associate general counsel and general manager of Microsoft’s Digital Crimes Unit. The page says Sep 22, 2026. It does not print an hour. The same-day technical account is the Microsoft Security Blog post, “Unmasking EvilTokens: Getting to the root of device code phishing,” by Microsoft Threat Intelligence, Microsoft Defender Experts, and Microsoft Security Research. That page also says September 22. The “15 min read” line is a reading-time label, not a clock. These lines are Microsoft’s. This desk did not seize a server.
