EvilTokens Hijacked Microsoft Logins, Coinbase Traces $1.1M

EvilTokens hijacked Microsoft logins and used AI for targeted phishing as Coinbase traced $1.1M in crypto revenue tied to the service.
Table of Contents

TL;DR:

  • EvilTokens compromised over 12,000 Microsoft inboxes across over 10,000 organizations by abusing device-code authentication and using AI to automate reconnaissance and impersonation.
  • Coinbase traced $1.1 million in EvilTokens revenue across four TRON addresses, clarifying that the figure represented platform payments rather than victim losses.
  • Microsoft and partners seized 50 websites and disabled over 150 domains, but the phishing method remains reusable because it exploits authentication and social engineering.

EvilTokens turned Microsoft’s device-code authentication flow into a phishing pipeline that compromised more than 12,000 inboxes across over 10,000 organizations. In its technical investigation, Microsoft said the platform used AI to tailor lures, analyze compromised mailboxes and identify employees involved in payments. The operation transformed trusted login infrastructure into a scalable business-email-compromise service, allowing attackers to gain authenticated access without stealing passwords and exploit inbox context to prepare targeted fraud.

AI Automation Made the Phishing More Scalable

Attackers initiated device-code sessions themselves, then sent victims codes through emails disguised as invoices, shared files and business communications. When a target entered the code on Microsoft’s legitimate site, the attacker’s waiting session became authorized. That workflow avoided capturing passwords directly while still giving criminals access to victim mailboxes. EvilTokens then automated tasks traditionally requiring manual reconnaissance, echoing the broader rise of AI-assisted crypto fraud across sophisticated social-engineering operations.

EvilTokens compromised over 12,000 Microsoft inboxes

 

Once inside, the platform could summarize messages, identify reporting lines, locate pending invoices and determine which employees had authority over payments. Investigators found evidence that AI-assisted coding tools helped build parts of the service. The combination lowered the technical burden for operators while making impersonation campaigns targeted and efficient. The attack model adds another layer to Microsoft-documented threats targeting crypto users, where trusted software or workflows can become attack surfaces when users are manipulated into authorizing access.

Crypto payments created a traceable trail. Coinbase’s Global Intelligence team tracked about $1.1 million in EvilTokens platform revenue across four TRON addresses between October 2025 and June 2026, identifying more than 1,000 deposits from over 700 addresses. The $1.1 million reflects payments made to EvilTokens, not confirmed losses suffered by phishing victims. Investigators combined blockchain data with merchant records, device information and open-source intelligence, showing how blockchain tracing and wallet security can complement broader cybercrime investigations.

Microsoft and its partners seized 50 websites and disabled more than 150 domains linked to the operation, while UK police arrested two men on September 11 before releasing them on conditional bail. The takedown disrupted the infrastructure, but it did not eliminate the underlying technique, which relies on legitimate authentication flows and social engineering rather than a software vulnerability. Microsoft recommends blocking device-code authentication where unnecessary, restricting it where required and rapidly revoking tokens when compromise is suspected.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews