Skip to content

Microsoft hits PhaaS platform EvilTokens in 40th cybercrime operation

Microsoft have taken down the phishing facilitator EvilTokens in a global operation in partnership with law enforcement and private-sector partners, such as Cloudflare.

Microsoft hits PhaaS platform EvilTokens in 40th cybercrime operation
Image credit: https://unsplash.com/@flyd2069

Microsoft's Digital Crimes Unit has disrupted the phishing-as-a-service operation EvilTokens in a joint operation with law enforcement and private-sector partners.

Microsoft has seized 50 websites and disabled 150 domains linked to EvilTokens, a sophisticated phishing-as-a-service (PhaaS) platform. The EvilTokens platform included a chatbot that helped criminals automate phishing campaigns, analyse compromised inboxes and identify targets for impersonation and fraud.

Two men, aged 32 and 38, have been arrested by London's Metropolitan Police as suspected website administrators. Their devices were seized before they were released on bail as the Met's cybercrime team's investigation continues.

EvilTokens illicitly accessed 12,000 inboxes across 10,000 organisations in a seven-month period, Microsoft said. Their service – which was sold through the encrypted messaging app Telegram – cost $1,500 upfront and $500-a-month thereafter, with users able to access phishing templates, domain and hosting configuration, a victim tracking dashboard and a range of other features for that price.

Cloudflare's Cloudforce One threat research team are among the groups to have collaborated with Microsoft in the takedown, purging domains, accounts and Workers projects used by EvilTokens after the group abused Cloudflare's platform to host phishing infrastructure.

40 and counting

This content is for members only

Subscribe
Add The Stack on Google