Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Simultaneously, EvilTokens employs a multi-stage delivery pipeline to bypass traditional email gateways and endpoint security through fake CAPTCHA checks and redirection chains that make use of high-reputation “serverless” platforms like Vercel, Cloudflare Workers, and AWS Lambda to blend in with legitimate enterprise cloud traffic and sidestep domain-blocklist triggers.

Statistics shared by Microsoft show that EvilTokens has been linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, indicating the service had gained widespread traction among threat actors in a short span of time.

The highest concentrations of victim activity have been observed in the U.S., Canada, the U.K., Australia, India, and France. Targeted organizations include wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

New ClosedQuorum Windows malware uses AI for attack decisions

A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.

The Go-based malware acts with no commands from a human operator, using reconnaissance information and a voting system to decide its next step on infected hosts.

When votes are tied, DeepSeek has priority at making the final call, based on the option it considers most appropriate, followed by Qwen, Mistral, and Gemini.

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU).

The phishing-as-a-service (PhaaS) operation emerged in February and was the first to support device code authentication at scale and offer cybercriminals AI-powered features for customizing lures and sifting through compromised inboxes to identify high-value targets.

In an announcement today, Microsoft said it coordinated the takedown of EvilTokens’ infrastructure, an action that involved the Health-ISAC, law enforcement, and SpyCloud, an identity threat protection company based in Austin, Texas.

/* */