微软于周二宣布取缔了名为 EvilTokens 的设备代码钓鱼服务,该服务被指在“攻击链的每一步”都使用了人工智能(AI)。
此次行动是在美国弗吉尼亚东区联邦法院授权下进行的,由 Health-ISAC 牵头,联合 Cloudflare、Coinbase、OpenAI、Railway、SpyCloud、Shadowserver Foundation 和 TRM Labs 共同开展。微软将开发和运营 EvilTokens 的威胁行为者追踪为 Storm-2992。
与此同时,大都会警察局于 2026 年 9 月 11 日逮捕了两名分别为 32 岁和 38 岁的男子,他们与该非法商业活动有关。这家科技巨头将 EvilTokens 描述为一个“强大的网络犯罪平台”,它利用 AI 来入侵电子邮件账户,并为金融欺诈和诈骗设计路线图。
微软数字犯罪部门的高级法律顾问兼总经理史蒂文·马萨达(Steven Masada)表示:“虽然 EvilTokens 帮助网络罪犯访问电子邮件账户,但该服务的核心是一个类 AI 聊天机器人,它可以分析受害者的收件箱,帮助罪犯识别可信关系、支付授权、敏感职责以及其他欺诈最有可能成功的情况。”
“该平台甚至能推荐欺诈策略,包括起草冒充可信联系人的消息,以帮助罪犯诱骗受害者采取行动。”
EvilTokens 最早于 2026 年 3 月由 Huntress 记录在案,它是一个钓鱼即服务(PhaaS)平台,滥用了 OAuth 2.0 设备授权流程,使攻击者无需提供任何凭据即可获取受害者账户的已认证会话。
被盗用的令牌被用于电子邮件外泄和持久化访问,通常通过设置隐藏通信内容的恶意收件箱规则来实现。在某些情况下,这些令牌还被滥用来允许新设备访问受害者的收件箱,从而为攻击者提供维持长期访问的替代途径。
这种恶意诱饵通常通过钓鱼攻击交付,向用户展示威胁行为者希望访问的服务的设备代码。受害者随后被提示在登录过程中的合法验证网址(例如 microsoft.com/devicelogin)输入此代码。
一旦提供代码,授权服务器就会向攻击者的客户端颁发访问令牌和刷新令牌,从而以受害者的身份授予其持续访问权限。
TRM Labs 表示:“EvilTokens 将账户接管、AI 驱动的邮箱分析和欺诈工具打包成一项单一的商业服务,降低了曾经需要具备的专业知识,以便大规模开展商业电子邮件入侵和发票欺诈。”
Sekoia 在 2026 年 3 月底发布的一份报告中将 EvilTokens 描述为一种现成解决方案,自 2 月中旬以来以 PhaaS 模式在 Telegram 上出售,为客户提供大量自托管钓鱼模板和 AI 驱动的功能,以自动化商业电子邮件入侵(BEC)工作流程,例如分析收集的电子邮件、识别与财务相关的邮件线程以及起草 BEC 邮件。
与 EvilTokens 相关的一些 Telegram 账户、频道和群组如下:
EvilTokens Admin - @eviltokensadmin, @eviltokensadmins 和 @EvilTokenscontact (备用)
EvilTokens Store - @EvilTokens_bot 和 @EvilTokensStorebot
公共频道 - @EvilTokensChannel
Telegram 群组 - https://t.me/+wNBoU1Gl2mRiYmU0
其他与 AI 相关的工具允许其客户总结和翻译电子邮件、映射组织角色、识别可信关系并推荐潜在目标。该服务还提供预设提示,以查找电汇讨论、识别组织的资金转移者、定位供应商发票以及确定最佳的冒充对象。
微软表示:“EvilTokens 将账户入侵、邮箱分析、目标筛选和欺诈准备整合到了单一服务中。曾经需要身份攻击、云系统、社会工程和金融欺诈等多方面经验才能掌握的能力,如今通过现成的界面即可获取。”
据发现,该威胁行为体提供了三种不同的产品:
EvilTokens B2B 发送器,售价 600 美元。
EvilTokens Office 365 捕获链接,售价 1500 美元。
EvilTokens SMTP 发送器,售价 1000 美元。
Sekoia 在 2026 年 4 月的一份后续报告中解释道:“‘Office 365 捕获链接’对应的是设备代码钓鱼工具包。” “一次性支付 1,500 美元的费用将授予附属人员终身访问 EvilTokens 管理面板的权限,以便查看窃取的 Microsoft 令牌。附属人员还必须每月支付 500 美元的许可费,以获得钓鱼页面代码以及用于后端集成和核心设备代码钓鱼功能的活跃 API 密钥。”
该服务还收取每月 500 美元的订阅费,以确保持续访问该工具包和控制面板。除了提供个性化诱饵和利用人工智能制作针对性钓鱼邮件的功能外,EvilTokens 还允许付费客户访问一整套辅助工具,包括 Antibot 重定向器、B2B 发送器、Office 365 捕获链接以及简单邮件传输协议(SMTP)发送器。
Coinbase 表示,它追踪到 2025 年 10 月至 2026 年 6 月期间,通过四个 Tron 地址获得了约 110 万美元的平台收入,并补充称,它识别出来自加密生态系统中超过 700 个独立地址的向 EvilTokens 进行的 1,000 多笔存款。
使用 EvilTokens 的攻击围绕发送利用 44 种不同主题的欺骗性电子邮件展开,其中包括发票和提案请求(RFP),或共享文件。这些消息包含恶意 URL、PDF 附件和 HTML 文件,以激活感染链:
同时,EvilTokens 采用多阶段交付管道,通过伪造的 CAPTCHA 检查和重定向链来绕过传统的电子邮件网关和端点安全机制,这些重定向链利用高信誉的“无服务器”平台(如 Vercel、Cloudflare Workers 和 AWS Lambda),以融入合法的云企业流量并规避域名黑名单触发器。
微软共享的统计数据显示,EvilTokens 已与全球超过 10,000 个组织的 12,000 多个被入侵邮箱相关联,表明该服务在威胁行为体中迅速获得了广泛的影响力。
受害者活动最集中的地区包括美国、加拿大、英国、澳大利亚、印度和法国。针对的组织包括批发分销、建筑、金融服务、房地产、高等教育和医疗保健行业。
微软表示,它与其他合作伙伴合作,查封了 50 个用于运营该服务的网站,并禁用了与其支持基础设施相关的另外 150 多个域名。
“EvilTokens 通过诱骗受害者在微软合法的登录页面上输入验证码,帮助犯罪分子获取了电子邮件账户的访问权限。通过完成正常的身份验证登录流程,受害者在不泄露密码的情况下,不知不觉地将电子邮件账户的访问权交给了犯罪分子。”微软解释道,“如果未同时撤销关联的会话和令牌,这种访问权限即使在重置密码后仍可能持续存在。”
此外,证据表明,该工具包的大部分功能是利用人工智能辅助开发的(即俗称的“氛围编码”),这表明该技术能够降低技能门槛,帮助 aspiring 网络犯罪分子开发高级工具包,并大规模实施欺诈行为。
Masada 补充道:“EvilTokens 将大部分欺诈流程打包成了一项商业运营服务,包括订阅定价、客户支持、管理仪表板以及旨在引导客户从账户访问转向金融剥削的工具。”
作为私营部门合作伙伴之一的 SpyCloud 表示,它通过分享重新捕获的钓鱼数据来支持此次破坏行动,这些数据包括被 EvilTokens 攻陷的 8,708 个独立受害者账户。这些账户涵盖了分布在 79 个国家的 6,585 个独立企业电子邮件域名。最早的捕获记录可追溯至 2026 年 2 月 18 日。
SpyCloud 的首席情报官 Trevor Hilligoss 在一份声明中表示:“EvilTokens 利用人工智能让困难的部分变得简单:阅读用二十多种语言编写的受损邮箱,以找到值得劫持的对话,并起草随后的冒充邮件。”“这些曾是商业电子邮件妥协(BEC)中需要人类参与的部分,并且其规模取决于犯罪分子的技能水平;EvilTokens 使其任何人都能以每月 500 美元的价格使用。”
“在一次行动中查封 50 个网站并禁用 150 个域名,只有当托管提供商、交换平台、模型提供者和数据持有者同时行动时才成为可能。EvilTokens 并非唯一值得破坏的网络钓鱼即服务平台,但其作为首个大规模实施设备代码网络钓鱼的平台这一地位,使得无论从哪个角度来看,这都是一次有意义的破坏行动。”
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain."
The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare , Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Microsoft is tracking the threat actors behind the development and support of EvilTokens as Storm-2992 .
In tandem, the Metropolitan Police Service arrested two men, aged 32 and 38, on September 11, 2026, in connection with the illicit commercial operation. The tech giant described EvilTokens as a "powerful cybercrime platform" that used AI to compromise email accounts and design roadmaps for financial fraud and scams.
"While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim's inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed," Steven Masada, associate general counsel and general manager at Microsoft's Digital Crimes Unit, said.
"The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action."
EvilTokens was first documented by Huntress in March 2026 as a phishing-as-a-service (PhaaS) platform that abused the OAuth 2.0 device authorization flow to give attackers authenticated sessions with victim accounts without having to supply any credentials at their end.
The stolen tokens are abused for email exfiltration and persistence, often by setting malicious inbox rules that conceal communications. In some cases, the tokens have also been abused to grant new devices access to a victim's inbox, thereby giving attackers an alternative pathway to maintaining long-term access.
The malicious lure, typically delivered via phishing attacks, shows the user a device code for the service that the threat actor wishes to access. The victim is then prompted to enter this code at the legitimate verification URL (e.g., microsoft.com/devicelogin) during the sign-in process.
Once the code is supplied, the authorization server issues access and refresh tokens to the attacker's client, granting them ongoing access under the victim's identity.
"EvilTokens packaged account takeover, AI-driven mailbox analysis, and fraud tooling into a single commercial service, lowering the expertise once needed to run business email compromise and invoice fraud at scale," TRM Labs said .
In a report published in late March 2026, Sekoia characterized EvilTokens as a turnkey solution sold under a PhaaS model on Telegram since mid-February, offering customers a plethora of self-hosted phishing templates and AI-powered features to automate business email compromise (BEC) workflows, such as analyzing harvested emails, identifying finance-related email threads, and drafting BEC emails.
Some of the Telegram accounts, channels, and groups linked to EvilTokens are below -
EvilTokens Admin - @eviltokensadmin, @eviltokensadmins, and @EvilTokenscontact (Backup)
EvilTokens Store - @EvilTokens_bot and @EvilTokensStorebot
Public channels - @EvilTokensChannel
Telegram group - https://t.me/+wNBoU1Gl2mRiYmU0
Other AI-related tools allowed its customers to summarize and translate emails, map organizational roles, identify trusted relationships, and recommend potential targets. The service also offered preset prompts to find wire-transfer discussions, identify an organization's money movers, locate vendor invoices, and determine the best people to impersonate.
"EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation in a single service," Microsoft said. "Capabilities that once required experience across identity attacks, cloud systems, social engineering, and financial fraud were available through a ready-made interface."
The threat actor has been found to offer three different products -
EvilTokens B2B sender, for $600.
EvilTokens Office 365 capture link, for $1500.
EvilTokens SMTP sender, for $1000
"The 'Office 365 capture link' corresponds to the device code phishing kit," Sekoia explained in a follow-up report in April 2026. "The one-time fee of $1,500 grants affiliates lifetime access to the EvilTokens administration panel for viewing harvested Microsoft tokens. Affiliates must also pay a monthly licence fee of $500 to obtain the phishing page code and an active API key for backend integration and core device code phishing functionality."
The service also charges a monthly subscription fee of $500 for continued access to the kit and control panel. Besides offering a way to personalize lures and use AI to craft targeted phishing emails, EvilTokens also allows paying customers to access a whole suite of auxiliary tools, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender.
Coinbase said it traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, adding that it identified more than 1,000 deposits to EvilTokens from over 700 distinct addresses across the crypto ecosystem.
Attacks using EvilTokens revolve around sending deceptive emails that make use of 44 different themes, including invoices and requests for proposals (RFPs), or shared files. These messages contain malicious URLs, PDF attachments, and HTML files to activate the infection chain -
Upon clicking a malicious link or attachment, redirect users to a web page running a background automation script.
The script interacts with the Microsoft identity provider in real time to generate a live device code.
Display the code on the user's screen with a "Copy Code" button along with a "Continue" or "Continue with Microsoft" button that, when clicked, takes the victim to the official microsoft.com/devicelogin portal.
The user pastes the code on the real Microsoft site.
If the user does not have an active Microsoft session, they are prompted to enter their credentials and multi-factor authentication (MFA) code.
The threat actor's session is authenticated, allowing them to register new devices, create malicious inbox rules, or exfiltrate sensitive email data.
Simultaneously, EvilTokens employs a multi-stage delivery pipeline to bypass traditional email gateways and endpoint security through fake CAPTCHA checks and redirection chains that make use of high-reputation "serverless" platforms like Vercel, Cloudflare Workers, and AWS Lambda to blend in with legitimate enterprise cloud traffic and sidestep domain-blocklist triggers.
Statistics shared by Microsoft show that EvilTokens has been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, indicating the service had gained widespread traction among threat actors in a short span of time.
The highest concentrations of victim activity have been observed in the U.S., Canada, the U.K., Australia, India, and France. Targeted organizations include wholesale distribution, construction, financial services, real estate, higher education, and healthcare.
Microsoft said it worked with other partners to seize 50 websites used to operate the service and disable over 150 additional domains associated with its supporting infrastructure.
"EvilTokens helped criminals gain access to email accounts by tricking victims into entering an authentication code on Microsoft's legitimate sign-in page. By completing the normal authentication sign-in process, victims unknowingly gave criminals access to their email accounts without revealing their passwords," Microsoft explained. "That access could persist even after a password reset if the associated sessions and tokens were not also revoked."
What's more, evidence points to large portions of the toolkit developed using AI assistance (aka vibe coded), signaling the technology's ability to lower skill barriers and help aspiring cybercriminals develop advanced toolkits and help perpetrate fraud at scale.
"EvilTokens packaged much of the fraud process into a commercially run service, complete with subscription pricing, customer support, management dashboards, and tools designed to move customers from account access toward financial exploitation," Masada added.
SpyCloud, which was one of the private sector partners, said it supported the disruption action by sharing recaptured phished data that included 8,708 unique victim accounts compromised by EvilTokens. These accounts span 6,585 unique corporate email domains located across 79 countries. The earliest captures date back to February 18, 2026.
"EvilTokens used AI to make the hard parts easy: reading compromised mailboxes in more than twenty languages to find the conversations worth hijacking, and drafting the impersonation mail that follows," Trevor Hilligoss, SpyCloud's Chief Intelligence Officer, said in a statement. "Those were the parts of business email compromise that used to require human involvement, and that scaled with the skill of the criminal; EvilTokens made them available to anyone for $500 a month."
"Fifty sites seized and 150 domains disabled in a single action is only possible when the hosting providers, the exchanges, the model providers and the data holders all move at the same time. EvilTokens isn't the only phishing-as-a-service platform deserving of a disruption, but its place as the first to implement device code phishing at scale makes this a meaningful disruption by any measure."
首次收录 · 2026-09-23 · 9.7 分