CONNECT WITH US
Web3 & Blockchain

Web3 & Blockchain

Coinbase traced $1.1 million crypto trail behind AI phishing service EvilTokens

CryptoSlate logo

Published on

Add as a preferred source on Google
Coinbase traced $1.1 million crypto trail behind AI phishing service EvilTokens

Microsoft and Coinbase helped dismantle EvilTokens, an AI phishing service tied to more than 12,000 compromised inboxes worldwide.

The operation had reached more than 10,000 organizations within months of launching, spanning financial services, real estate, healthcare, construction and other industries, Microsoft said.

The company and its partners seized 50 websites used by EvilTokens and disabled more than 150 related domains, while UK police arrested two men on Sept. 11 on suspicion of offenses connected to the alleged operation. Police later released both on conditional bail.

EvilTokens had packaged much of the business-email-compromise process into a subscription service sold through Telegram. Microsoft said customers paid a $1,500 initiation fee and $500 recurring subscription for tools that combined account compromise, mailbox access, reconnaissance, and AI-assisted fraud preparation in a single interface.

The service’s entry point relied on Microsoft’s device-code authentication, a legitimate sign-in flow designed for hardware such as smart TVs and conferencing equipment that cannot easily support standard browser logins.

Attackers initiated the authentication request themselves, then sent the resulting code to targets through phishing emails disguised as invoices, shared files, and other routine business communications.

Victims who entered that code on Microsoft’s legitimate website effectively approved the session waiting on the attacker’s device.

The process could still require a password and multifactor authentication when the user was signed out, but those credentials remained on Microsoft’s infrastructure. The process generated authorization for the attacker-initiated session.

That gave EvilTokens something more useful than a stolen password: an authenticated foothold inside the mailbox.


Source link

Disclaimer

We strive to uphold the highest ethical standards in all of our reporting and coverage. We TheMorningPulse.fyi want to be transparent with our readers about any potential conflicts of interest that may arise in our work. It's possible that some of the investors we feature may have connections to other businesses, including competitors or companies we write about. However, we want to assure our readers that this will not have any impact on the integrity or impartiality of our reporting. We are committed to delivering accurate, unbiased news and information to our audience, and we will continue to uphold our ethics and principles in all of our work. Thank you for your trust and support.