Microsoft has successfully disrupted a subscription-based scam platform known as EvilTokens, which utilized an AI chatbot to infiltrate over 12,000 Microsoft accounts within a few months. Emerging on a Telegram channel in February, EvilTokens charged users an initial fee of $1,500, followed by a monthly subscription of $500.
This platform provided a comprehensive service that streamlined the process of compromising email accounts en masse. According to Microsoft, once users gained access through EvilTokens, the platform enabled them to navigate victims’ inboxes, select potential targets, and even craft deceptive emails aimed at convincing employees to transfer funds to accounts controlled by the scammers.
Microsoft says that while it also attacked specific countries, its significance extends beyond its rapid growth and global reach. What set EvilTokens apart was the AI-style chatbot sitting at the heart of the operation, according to Microsoft. The chatbot could analyse a victim’s inbox and help criminals pinpoint trusted relationships, payment approval authority, sensitive job responsibilities and other circumstances where fraud was most likely to succeed. It could even go a step further, recommending specific fraud strategies and drafting messages impersonating trusted contacts to manipulate victims into taking action. The victim would then see this device code onscreen, along with instructions telling them to copy it and enter it into Microsoft’s official device login portal. Behind the scenes, complex backend operations allowed the hackers slip past traditional signature- or pattern-based security detection systems. This technique powered the entire attack chain, from generating dynamic device codes all the way through to actions taken after an account was compromised.

