Microsoft and Coinbase have helped disrupt EvilTokens, an AI-powered phishing service linked to more than 12,000 compromised inboxes worldwide.
Microsoft said the operation had reached more than 10,000 organisations within months of launching, targeting sectors including financial services, real estate, healthcare and construction.
Fifty websites used by EvilTokens were seized and more than 150 associated domains disabled. UK police arrested two men on 11 September on suspicion of offences connected to the alleged operation. Both were later released on conditional bail.
EvilTokens sold business email compromise tools through Telegram, offering customers an entry package costing $1,500 followed by a $500 recurring subscription. The service combined account compromise, mailbox access, reconnaissance and AI-assisted fraud preparation.
Its access method exploited Microsoft’s device-code authentication system, a legitimate sign-in process intended for equipment such as smart TVs and conference devices that cannot easily use a standard browser login.
Attackers generated an authentication request and sent the resulting code to targets in emails disguised as invoices, shared documents and other routine business messages. Anyone entering the code on Microsoft’s legitimate website effectively authorised a session already waiting on the attacker’s device.
A password and multifactor authentication could still be required if the user was signed out, but those credentials remained on Microsoft’s infrastructure. The process instead granted authorisation to the attacker-initiated session, giving criminals an authenticated presence in the mailbox rather than simply a stolen password.
EvilTokens then used AI to translate and summarise messages, identify reporting lines and trusted contacts, find pending invoices and wire-transfer discussions, and establish which employees could approve payments.
Microsoft said preset prompts could identify an organisation’s “money movers” and suggest people to impersonate, reducing the manual work needed to turn mailbox access into a targeted fraud campaign. Investigators also found evidence that AI-assisted coding tools had been used to build parts of the service.
Crypto trail
The subscription payments provided Coinbase with a route into the alleged operation. Its Global Intelligence team traced about $1.1m in EvilTokens revenue across four Tron addresses between October 2025 and June 2026.
It identified more than 1,000 deposits from more than 700 separate addresses and followed the money from payments to EvilTokens through to eventual cash-out destinations. The figure represents revenue paid to the service, not the total amount stolen from phishing victims.
Coinbase said it combined blockchain transactions with merchant records, device data and open-source intelligence before attributing the platform to its alleged operators and referring the case to London’s Metropolitan Police.
The exchange also identified EvilTokens customers using its platform and referred those cases to law enforcement. Its evidence contributed to Microsoft’s civil action against the service.
Some Coinbase customers were targeted after attackers compromised email conversations and persuaded them to send cryptocurrency to scam-controlled addresses. Coinbase said its accounts and credentials were not compromised.
The operator had signalled plans to extend the toolkit to Gmail and Okta accounts, according to Coinbase, raising the possibility of the same model being used across other identity platforms.
Microsoft said dismantling the current infrastructure would not remove the underlying technique. It recommends blocking device-code authentication where it is unnecessary and tightly restricting it where it is required.
For suspected compromises, the company advises revoking refresh tokens, requiring users to authenticate again and, in some cases, temporarily disabling the account. Microsoft warned that standard session revocation may leave existing access tokens active for up to an hour, creating a choice between short-term disruption and continued attacker access.
