$ techbeacon▋
Phishing

EvilTokens Phishing Kit Dismantled After Hijacking Thousands of Inboxes

EvilTokens Phishing Kit Dismantled After Hijacking Thousands of Inboxes

Microsoft, Coinbase and a coalition of law‑enforcement agencies announced the shutdown of EvilTokens, a phishing‑as‑a‑service platform that infiltrated more than 12,000 email accounts in a matter of months after its emergence in February 2026.

The service leveraged a combination of device‑code phishing—a technique that tricks users into authorizing malicious applications on their devices—and artificial‑intelligence generated content to make its lure appear legitimate. By automating the creation of convincing messages, EvilTokens was able to scale quickly, compromising inboxes across at least 10,000 distinct victims.

Security researchers first flagged the kit in early 2026, noting its modular architecture that allowed attackers to rent the infrastructure without deep technical expertise. The model mirrored earlier phishing‑as‑a‑service operations but stood out for its integration of AI, which generated context‑aware subject lines and body text, reducing the need for manual crafting of each campaign.

Microsoft’s threat‑intelligence team traced the command‑and‑control servers to a hosting provider that was later identified as a conduit for multiple illicit services. Simultaneously, Coinbase’s security division provided crucial transaction data that linked cryptocurrency payouts to the operators, helping authorities map the financial flow behind the scheme.

Law‑enforcement officials, in coordination with the private‑sector partners, seized the servers, disrupted the payment channels and issued takedown notices that removed the kit’s hosting infrastructure from the internet. The operation also resulted in the arrest of several individuals believed to be responsible for managing the service, though details of the arrests remain under investigation.

Experts say the takedown underscores the growing convergence of cybercrime and financial technology. “When phishing kits start integrating AI and crypto‑based monetization, the threat landscape evolves faster than traditional defenses,” said a senior analyst at a cybersecurity firm who chose to remain unnamed. The analyst added that the incident highlights the importance of cross‑industry collaboration in confronting such hybrid threats.

For users, the breach serves as a reminder to scrutinize unexpected authentication prompts, especially those that request device‑code approvals. Organizations are urged to enforce multi‑factor authentication, monitor for anomalous login patterns and educate employees about the subtleties of AI‑generated phishing content.

While the removal of EvilTokens marks a significant victory, security professionals caution that the underlying techniques are likely to be repackaged by other actors. The rapid adoption of AI in malicious campaigns suggests that future phishing‑as‑a‑service offerings could emerge with even more sophisticated deception capabilities, keeping defenders on high alert.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related