• Microsoft takes down AI-boosted phishing tool that hit 12,000 acc

    From TechnologyDaily@1337:1/100 to All on Wednesday, September 23, 2026 17:15:20
    Microsoft takes down AI-boosted phishing tool that hit 12,000 accounts

    Date:
    Wed, 23 Sep 2026 16:05:00 +0000

    Description:
    Two people arrested and dozens of websites seized in an organized operation against EvilTokens.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft, UK police, and partners disrupted EvilTokens PhaaS, arresting two suspects and seizing 200+ domains/sites EvilTokens used AI to scale devicecode phishing, compromising 12,000 inboxes across 10,000 organizations globally Platform ran like a startup with subscriptions, dashboards, and AIdriven targeting; US victims
    hit hardest Two people have been arrested, 50 websites were seized, and 150 domains disabled, in a joint operation against the infamous EvilTokens phishing-as-a-service (PhaaS) kit.

    In its report , Microsoft said the UK Metropolitan Police Services cybercrime team arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens. The two men, whose identities were not disclosed,
    are aged 32 and 38, and have been released on bail, subject to conditions while the investigation continues. Their digital services and other items
    have been confiscated, as well. Latest Videos From TechRadar Watch full video here:

    Among the partners are Health-ISAC, Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. We dont know if these arrests and takedowns will be enough to completely obliterate EvilTokens, or if the platform will continue to operate. Usually, criminal infrastructure is a lot less resilient to disruptions when arrests are made, compared to when law enforcement simply disables the hardware. The tech startup of organized crime EvilTokens has been turning heads for a little while now. The platform was first spotted in February 2026, rising quickly to become one of the most widely used PhaaS solutions out there. You may like Microsoft 365 users hit
    by phishing scheme posing as RingCentral emails Microsoft, Google took down $66 million cybercrime marketplace that sold virtual machines with free software NightmareStresser group responsible for thousands of DDOS attacks
    has domains seized in major operation

    It can be bought through Telegram for $1,500, after which there is a
    recurring $500 subscription cost. Cybercriminals use it to run large-scale, personalized phishing attacks: they can create spoofed websites, landing pages, and other credential-capture assets; they can create custom-tailored phishing emails, and can even grab session tokens, one-time passwords , and other codes designed to protect accounts against phishing, granting attackers access to peoples inboxes.

    But what makes EvilTokens particularly impressive is its use of artificial intelligence. The platform comes with an AI assistant that can sift through the inboxes, suggest which targets are of high value, and even how to
    approach them. Attackers can conduct Microsoft Graph reconnaissance as well, mapping out organizational structure and permissions, keeping access and moving laterally throughout the target network. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    Microsoft said it found evidence of large portions of EvilTokens being vibe coded, with AI helping its creators build the platform itself.

    The researchers also found the platform drawing on capabilities from multiple AI models. Looking at the platform as a whole, it runs like a well-organized startup, with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation.

    According to Microsoft, EvilTokens facilitated business email compromise
    (BEC) campaigns that compromised more than 12,000 inboxes in more than 10,000 organizations worldwide. Victims are mostly in wholesale distribution, construction, and financial services, but those in real estate, higher education, and healthcare are not spared, either. What to read next Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world $293 million seized and 5,811 arrests made in huge anti-scam and fraud action by Interpol and law enforcement agencies across 97 countries A botnet running for 23 years with over 15,000 endpoints has finally been shut down by law enforcement and Crowdstrike

    The victims are primarily located in the United States, with notable numbers found in Canada, the United Kingdom, Australia, India, and France. Microsoft said affected customers were notified, and that the company helped remediate compromised accounts and shared intelligence to support further defensive and investigative action." Popularizing device-code phishing Device-code phishing as an attack technique is not that new. More than a year ago, in February 2025, security researchers Huntress reported on Russian threat actors Storm-2372 deploying the same technique, and while its been steadily growing in popularity, it wasnt until EvilTokens appearance that it really exploded.

    The same researchers said, in June 2026 , that EvilTokens was used to run 1,380% more device-code phishing attacks in 2026, compared to the same period last year.

    Were seeing a clear maturation of the phishing-as-a-service (PhaaS) market as threat actors increasingly integrate AI workflows into their product offerings, Huntress said in a report.

    The result is directly observable in our telemetry: a 1,380% increase in device code phishing attacks detected between JulyDecember 2025 and JanuaryApril 2026, with over 50% of those incidents linked to two major waves of correlated incidents. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/microsoft-takes-down-ai-boosted-phishin g-tool-that-hit-12-000-accounts


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)