Microsoft 携手多方打击用 AI 聊天机器人窃取 12,000 个账号的 EvilTokens 订阅诈骗平台

Ars Technica:AI(RSS)·2026-09-23 03:45·4小时前· Dan Goodin
AI 导读

Microsoft 周二宣布主导行业联合行动,打击通过 Telegram 频道运营的订阅制诈骗平台 EvilTokens,该平台用 AI 聊天机器人分析受害者收件箱、识别可信关系并起草冒充可信联系人的诈骗邮件,几个月内入侵了全球 10,000 个组织的 12,000 个 Microsoft 账号,受影响最集中的国家依次为美国、加拿大、英国、澳大利亚、印度和法国。

Ars Technica:AI(RSS)
68AI 编辑部评分,满分 100

Microsoft 携手多方打击用 AI 聊天机器人窃取 12,000 个账号的 EvilTokens 订阅诈骗平台

2026-09-23 03:45· 4小时前· Dan Goodin
AI 导读

Microsoft 周二宣布主导行业联合行动,打击通过 Telegram 频道运营的订阅制诈骗平台 EvilTokens,该平台用 AI 聊天机器人分析受害者收件箱、识别可信关系并起草冒充可信联系人的诈骗邮件,几个月内入侵了全球 10,000 个组织的 12,000 个 Microsoft 账号,受影响最集中的国家依次为美国、加拿大、英国、澳大利亚、印度和法国。

Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span.

Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts.

Minutes, not days

“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.”

Microsoft said users of EvilToken compromised 12,000 customer accounts belonging to 10,000 organizations around the world, with the highest concentration of them located in the US. Countries with the next-largest numbers were Canada, the UK, Australia, India, and France. Victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm that assisted in the disruption operation, has more details about victims here.

Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform.

Ars Video

How The Callisto Protocol's Gameplay Was Perfected Months Before Release

Account compromises were achieved through a legitimate OAuth process known as device code authentication. This form of authentication is designed for TVs and input-constrained devices, meaning those that lack the interface for performing normal log-in processes. In this model, the device being signed into presents a code and instructs the user to enter it into a browser on a separate device. The new device is then authenticated.

来源:Ars Technica:AI(RSS)· arstechnica.com