Microsoft Disrupts EvilTokens, an AI-Powered Phishing Cybercrime Platform
Microsoft and its partners disrupted EvilTokens, an AI-assisted cybercrime platform operating on a subscription model that enabled automated mass account compromises affecting over 12,000 targets. This disruption highlights the growing threat of AI-enabled cybercrime platforms that lower the technical barrier for attackers to bypass multi-factor authentication (MFA) at scale. It demonstrates how law enforcement and major technology companies are aggressively targeting Phishing-as-a-Service (PaaS) infrastructure. EvilTokens operated under a subscription model, charging cybercriminals a $1,500 initiation fee and $500 per month for platform access. The service utilized AI capabilities and specialized in automated device code phishing to bypass traditional MFA security controls.
## BACKGROUND
Phishing-as-a-Service (PaaS) platforms provide ready-to-use tools, infrastructure, and automated features that allow attackers with minimal technical skills to launch phishing campaigns. Multi-factor authentication (MFA) is a critical security layer that verifies user identity through multiple steps, but advanced phishing techniques can intercept session tokens or exploit device authorization flows to bypass it.