Crypto
Home›Crypto›Regulation›Coinbase traced $1.1 million crypto trail tied to AI p…
Coinbase traced $1.1 million crypto trail tied to AI phishing service
EvilTokens was linked to more than 12,000 compromised inboxes and relied on Microsoft device-code authentication to gain authenticated access, UK police said two men were arrested on Sept. 11.
Microsoft and Coinbase helped dismantle EvilTokens, an AI phishing service tied to more than 12,000 compromised inboxes worldwide, with the operation reaching more than 10,000 organizations within months of launching, Microsoft said. The effort involved seizing 50 websites used by EvilTokens and disabling more than 150 related domains, while UK police arrested two men on Sept. 11 on suspicion of offenses connected to the alleged operation, according to the companies and police.
Investigators described EvilTokens as packaging parts of the business-email-compromise workflow into a subscription service sold through Telegram. Microsoft said customers paid a $1,500 initiation fee and $500 recurring subscription for tools that combined account compromise, mailbox access, reconnaissance, and AI-assisted fraud preparation in a single interface.
The service’s entry point relied on Microsoft’s device-code authentication, a legitimate sign-in flow for hardware such as smart TVs and conferencing equipment that cannot easily support standard browser logins. Attackers initiated authentication requests and then sent targets the resulting code through phishing emails disguised as invoices, shared files, and other routine business communications, allowing victims to approve an attacker-initiated session on Microsoft’s website.
With that authenticated foothold inside captured mailboxes, EvilTokens used AI tools to translate and summarize messages, identify reporting lines and trusted contacts, and surface pending invoices and wire-transfer conversations. Microsoft said preset prompts could identify an organization’s “money movers” and recommend people to impersonate, potentially reducing the manual reconnaissance required for targeted fraud.