Microsoft Takes Action Against AI-Enhanced Platform Compromising 12,000 Accounts

Microsoft announced a significant disruption of a subscription-based scam platform known as EvilTokens, which utilized an AI chatbot to breach approximately 12,000 Microsoft accounts over a span of several months. The platform was launched on a Telegram channel in February, requiring an upfront payment of $1,500 and a monthly fee of $500 thereafter. EvilTokens was designed to simplify various processes related to the mass compromise of email accounts, allowing users to efficiently analyze inboxes, identify high-value targets, and create follow-up communications that convincingly impersonated legitimate contacts to deceive recipients into transferring funds.

EvilTokens housed a sophisticated AI chatbot that played a pivotal role in aiding cybercriminals. According to Microsoft, the chatbot could scrutinize a victim’s inbox, revealing trusted connections, payment authorizations, and sensitive obligations that would increase the likelihood of fraud. The platform also provided tactical recommendations for deception, helping users draft emails that mimicked those from trusted individuals, thereby enhancing the chances of successful scams.

In total, users of EvilTokens compromised accounts belonging to around 10,000 organizations globally, with the largest number of affected accounts situated in the United States. Following the United States, Canada, the United Kingdom, Australia, India, and France were noted as having significant victim numbers. Industries targeted included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. Security firm SpyCloud, which collaborated with Microsoft during the operation, has detailed further insights about the impacted organizations.

Employing a legal framework and an extensive network of partners, Microsoft successfully seized 50 websites and an additional 150 domains associated with the EvilTokens platform. The UK’s Metropolitan Police Service apprehended two individuals suspected of being involved in operations related to the crime network.

The attacks primarily exploited a legitimate OAuth process called device code authentication, intended for devices with limited input capabilities such as TVs. This authentication method requires users to input a code displayed on their device into a separate browser on a different device, thereby allowing for secure authentication even on devices that cannot perform standard login procedures.

From a cybersecurity perspective, this incident highlights several key tactics and techniques from the MITRE ATT&CK framework that may have been utilized in the execution of this attack. The initial access to compromised accounts could align with techniques designed for credential harvesting, while the use of AI chatbots suggests potential application of social engineering tactics to enhance the effectiveness of deception and maintain persistence within the victim’s environment. By leveraging advanced analytical capabilities, the attackers could manipulate trust relationships and hone in on sensitive transactions, ultimately escalating privileges to execute their fraudulent schemes.

As this incident illustrates, the evolving landscape of cyber threats requires constant vigilance and updated defenses. Organizations must prioritize robust authentication methods and employee training to mitigate such risks and protect sensitive information from increasingly sophisticated adversaries.

Source