Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
Microsoft has disrupted an AI-powered cybercrime platform known as EvilTokens after obtaining federal court authorization to seize and disable infrastructure used to compromise email accounts, automate phishing attacks, analyze stolen inboxes, and identify opportunities for financial fraud.
The coordinated action involved Microsoft’s Digital Crimes Unit, Health-ISAC, technology and cybersecurity partners, and the Metropolitan Police Service in the United Kingdom. Microsoft said the platform had been linked to more than 12,000 compromised email inboxes across more than 10,000 organizations worldwide since emerging in February 2026.
The highest concentrations of victim activity identified by Microsoft were in the United States, Canada, the United Kingdom, Australia, India, and France. Organizations affected by the operation spanned multiple sectors, including financial services, health care, higher education, construction, real estate, and wholesale distribution.
EvilTokens operated as a commercial phishing-as-a-service platform distributed through Telegram. Microsoft said customers paid an initial $1,500 fee followed by a recurring $500 monthly subscription for continued access to the service and its management panel. Additional criminal tools could also be purchased separately.
The service combined several phases of a cyberattack that traditionally required separate tools and significant manual effort. EvilTokens provided phishing infrastructure, account-compromise capabilities, victim tracking, prebuilt templates, token theft, mailbox analysis, artificial intelligence assistance, and tools intended to help criminals turn access to a compromised account into financial fraud.
Microsoft said the central feature was an AI-style chatbot capable of analyzing the contents of compromised email inboxes. The system could summarize and translate messages, identify financial conversations, map organizational relationships, locate vendor invoices, identify employees authorized to move money, and recommend individuals whom attackers could impersonate.
That capability changed the speed of post-compromise activity.
A criminal who previously gained access to a large corporate inbox might need days to examine messages, learn internal relationships, locate payment discussions, and determine which employees or vendors could be impersonated. EvilTokens automated much of that process, allowing attackers to identify valuable information and fraud opportunities much faster.
Microsoft said preset prompts could search for wire-transfer conversations, identify an organization’s financial decision-makers, locate invoices, map trusted relationships, and suggest targets for impersonation. The system could then assist in drafting fraudulent messages intended to exploit those relationships.
The platform also relied heavily on device-code phishing, an attack method that abuses a legitimate authentication mechanism used by devices that cannot easily support conventional interactive login screens.
Device-code authentication is commonly used with devices such as smart televisions, printers, conferencing systems, and Microsoft Teams hardware. A legitimate device generates a temporary code that the user enters into a browser on another device to authorize access.
EvilTokens weaponized that process.
According to Microsoft Threat Intelligence, the attacker initiated the authentication request and delivered the generated device code to the victim through a phishing lure. When the victim entered the code into Microsoft’s legitimate authentication page, the victim was not giving the attacker a password. The victim was unknowingly authorizing the attacker’s session.
That distinction can make the attack difficult for victims to recognize because the user may ultimately interact with a legitimate Microsoft sign-in page rather than a counterfeit password form.
Once authorization was completed, stolen authentication tokens could provide access to the victim’s email account. Microsoft said access could remain active even after a password change if associated sessions and tokens were not revoked. Attackers could also create malicious inbox rules or register additional devices to help maintain access.
Microsoft identified 44 different phishing themes used by EvilTokens campaigns, including invoices, shared-file notifications, requests for proposals, and other business communications. Malicious emails could contain links, PDF attachments, HTML files, or other content designed to direct victims into the device-code authentication process.
The company tracks the developer and support operation behind the EvilTokens phishing kit as Storm-2992. Microsoft said the service used Telegram for advertising, subscription sales, product updates, customer support, and communication with users.
Investigators also determined that substantial portions of EvilTokens itself had been created through AI-assisted development, a practice sometimes described as “vibe coding.” Microsoft said the platform drew capabilities from multiple AI models and packaged those technologies into a criminal service equipped with customer support, management dashboards, and automated fraud tools.
The result was not simply an AI system producing phishing messages. It was an integrated criminal platform designed to help attackers move from initial deception to account compromise, internal reconnaissance, victim selection, impersonation, and financial exploitation.
Microsoft and Health-ISAC took the operation to federal court.
Records published by Microsoft show that the companies filed Civil Action No. 1:26-cv-3047 in the U.S. District Court for the Eastern District of Virginia against Felix Utomi, Waidi Segun Adams, and Does 1 through 5. The civil complaint alleges that the defendants operated cybercriminal infrastructure that caused unauthorized access to computer systems, deception, and violations affecting Microsoft and its customers. Those allegations remain part of an ongoing civil proceeding and should not be treated as criminal convictions.
The federal court granted Microsoft a temporary restraining order authorizing action against domains associated with the operation. The order allowed registries and registrars to transfer or disable targeted domains and preserve associated content and infrastructure while the case proceeds. Microsoft is seeking additional injunctive relief and damages.
Microsoft said the disruption resulted in the seizure of 50 websites used by EvilTokens and the disabling of more than 150 additional domains connected to supporting infrastructure.
Health-ISAC joined Microsoft as a co-plaintiff because health care organizations were among the victims of EvilTokens campaigns. The disruption also involved Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Microsoft said affected customers were notified and assisted with remediation while intelligence was shared with law enforcement and defenders.
The investigation also led to arrests in the United Kingdom.
Microsoft said Metropolitan Police Service cybercrime officers arrested two men, ages 32 and 38, on September 11 after intelligence from Microsoft supported law-enforcement action. Officers seized digital devices and other material for examination. Both men were later released on police bail subject to conditions while the investigation continues.
The arrests remain investigative actions rather than findings of guilt.
Microsoft has not publicly identified the two arrested men in its September 22 announcement, and the available official information does not establish that the individuals named as defendants in the U.S. civil action are the same two men arrested in Britain. Those matters should remain separate unless law enforcement or court records formally connect them.
The disruption marks the Microsoft Digital Crimes Unit’s 40th court-authorized operation targeting cybercrime or malicious infrastructure and its first directed against what the company describes as an end-to-end AI-enabled cybercrime service.
Microsoft’s Digital Crimes Unit has used civil litigation, technical disruption, criminal referrals, threat intelligence, and partnerships with governments and private companies to interfere with malicious infrastructure since 2008. The unit has previously targeted botnets, phishing operations, malware delivery networks, credential-theft platforms, and infrastructure supporting nation-state activity.
The EvilTokens operation represents a significant development because AI was embedded throughout the criminal workflow instead of being used for one isolated function.
Traditional phishing platforms can provide fake login pages and email templates. EvilTokens added automated analysis after the account was compromised. The platform could examine the victim’s actual communications and use that information to identify relationships that carried financial authority or trust.
That creates a more dangerous form of business email compromise.
An attacker entering a corporate mailbox can potentially identify who approves wire transfers, which vendors regularly receive payments, who works with senior executives, how invoices are formatted, what projects are underway, and which conversations can be manipulated without immediately appearing suspicious.
AI allows that information to be processed at machine speed.
Microsoft said organizations should operate under the assumption that once a mailbox is compromised, criminals may be capable of understanding its contents within minutes rather than requiring prolonged manual analysis.
The company recommends stronger identity protections, close monitoring of authentication activity, restrictions on device-code authentication where it is not required, and independent verification of requests involving payment changes, fund transfers, or unusual financial instructions.
Microsoft specifically advises organizations that do not need device-code authentication to block the flow. Environments that require it for legitimate equipment should narrowly restrict its use to approved device accounts and monitor authentication activity for anomalies.
Organizations responding to suspected compromise should also understand that changing a password may not terminate a stolen session. Existing authentication tokens, registered devices, malicious inbox rules, and other persistence mechanisms may need to be revoked or removed separately.
EvilTokens demonstrates a broader shift in the cybercrime economy.
AI is lowering the expertise required to perform tasks that once demanded separate experience in phishing, cloud authentication, social engineering, data analysis, organizational reconnaissance, and financial fraud. A subscription service can now combine many of those functions behind a single interface.
That does not eliminate the need for attackers to gain access.
It changes what they can do once access is obtained.
A compromised inbox is no longer only a source of stolen messages. With automated analysis, it can become a map of an organization’s financial relationships, hierarchy, vendors, trusted contacts, and payment processes.
The September disruption removed a major portion of EvilTokens infrastructure and produced two arrests in Britain, but Microsoft cautioned that the model demonstrated by the service is unlikely to disappear with one operation.
The central security problem is broader than EvilTokens itself.
Cybercriminal platforms are beginning to combine phishing infrastructure, stolen authentication tokens, automated reconnaissance, AI-assisted decision-making, impersonation, and financial exploitation into unified services.
That convergence compresses the time between compromise and fraud.
For defenders, the window to identify and contain a breached account is getting smaller.
Microsoft Digital Crimes Unit — EvilTokens, litigation notice and court filing index, U.S. District Court for the Eastern District of Virginia, Civil Action No. 1:26-cv-3047. (Free Download)
Microsoft Corporation and Health-ISAC, Inc. v. Felix Utomi, Waidi Segun Adams, and Does 1–5 — Federal Complaint, U.S. District Court for the Eastern District of Virginia. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



