Microsoft disrupts AI-assisted platform that compromised 12,000
Mirrored from Ars Technica — AI for archival readability. Support the source by reading on the original site.
Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span.
Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts.
Minutes, not days
“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”
Microsoft said users of EvilToken compromised 12,000 customer accounts belonging to 10,000 organizations around the world, with the highest concentration of them located in the US. Countries with the next-largest numbers were Canada, the UK, Australia, India, and France. Victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm that assisted in the disruption operation, has more details about victims here.
Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform.
Account compromises were achieved through a legitimate OAuth process known as device code authentication. This form of authentication is designed for TVs and input-constrained devices, meaning those that lack the interface for performing normal log-in processes. In this model, the device being signed into presents a code and instructs the user to enter it into a browser on a separate device. The new device is then authenticated.
EvilTokens provided customers with a platform that automated the sending of large numbers of spam. Users who clicked on malicious links or attachments in the emails were directed to a webpage running a hidden automation script that interacts with the user’s Microsoft identity provider in real time to generate a code for enrolling a device belonging to the attacker. SpyCloud identified the ID provider as Microsoft Entra.
The user would then see the device code along with instructions to copy it and enter it into the official Microsoft device login portal. Complex backend logic (Node.js) in the platform allowed the operation to bypass traditional signature-based or pattern-based detection. The technique allowed the process to work end to end, from the generation of dynamic device codes to post-compromise activities. Microsoft has more on the abuse of the OAuth process here.
A dashboard allowed users to tailor lures to the profiles of the organizations they were targeting. The platform largely automated the rest of the attack process as well. EvilTokens analyzed 5,000 compromised emails at a time. Using AI, the platform identified employees authorized to disburse large sums of money, managers these employees reported to, and convincing scenarios under which the manager or others could persuade the employees to transfer money into what turned out to be attacker-controlled accounts.
Microsoft said that EvilTokens represents a major shift in the mass compromise and post-compromise of accounts. Normally, it took time for attackers to sift through thousands of emails to assemble the organization’s management chart, suppliers, customers, and other relationships with third parties. That burden is greatly reduced with AI-assisted tools.
“For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” Microsoft said. “Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.”
More from Ars Technica — AI
-
New Anthropic, OpenAI models make same promise: A little more for a lot less money
Sep 22
-
Lawsuit demands OpenAI pay for new school after ChatGPT used in shooting
Sep 22
-
Toyota orders workers to train humanoid robots but says humans won't be replaced
Sep 22
-
Dyson’s most overengineered gadget may have a waterproofing problem
Sep 22
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.