Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • ଦେଶ ବିଦେଶ
  • ଜିଲ୍ଲା
  • ରାଜ୍ୟ
  • ଓଡିଶା
  • ରାଜନୀତି
  • ଅର୍ଥନୀତି
  • ବାଣିଜ୍ୟ
  • ଅପରାଧ
  • ଖେଳ
  • ଦେଶ ବିଦେଶ
  • ଜିଲ୍ଲା
  • ରାଜ୍ୟ
  • ଓଡିଶା
  • ରାଜନୀତି
  • ଅର୍ଥନୀତି
  • ବାଣିଜ୍ୟ
  • ଅପରାଧ
  • ଖେଳ

Archives

  • September 2026
  • August 2026
  • July 2026

Categories

  • Uncategorized
  • ଓଡିଶା
  • ଜିଲ୍ଲା
  • ଦେଶ ବିଦେଶ
  • ଦେଶ ବିଦେଶ
  • ଜିଲ୍ଲା
  • ରାଜ୍ୟ
  • ଓଡିଶା
  • ରାଜନୀତି
  • ଅର୍ଥନୀତି
  • ବାଣିଜ୍ୟ
  • ଅପରାଧ
  • ଖେଳ
Subscribe
Close

Search

ଦେଶ ବିଦେଶ

Microsoft says it has taken down ‘AI chatbot built for cybercrime’ that hacked 12,000-plus emails across over 10,000 organisations globally

By admin
September 24, 2026 3 Min Read
0
Spread the love


Microsoft says it has taken down ‘AI chatbot built for cybercrime’ that hacked 12,000-plus emails across over 10,000 organisations globally

Microsoft has said that it has thwarted an effort to shut down a subscription-based scam platform that relied on an AI chatbot to break into more than 12,000 Microsoft accounts over the course of a few months. The platform, called EvilTokens, first surfaced on a Telegram channel back in February, charging users an initial fee of $1,500 followed by a recurring monthly charge of $500. EvilTokens essentially offered a one-stop service that streamlined nearly every step needed to compromise email accounts at scale. According to the company, once inside, the platform helped its customers sift through victims’ inboxes, identify the most targets and even draft follow-up emails designed to trick employees into transferring funds into accounts controlled by the attackers.“In short, AI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,” the company said.

Targets in several countries, including India

Microsoft says that while it also attacked specific countries, its significance extends beyond its rapid growth and global reach.“Microsoft observed the highest concentrations of victim activity in the United States, Canada, the United Kingdom, Australia, India, and France. Affected organizations ranged from wholesale distribution and construction to financial services, real estate, higher education, and healthcare. Working with partners, Microsoft seized 50 websites used to operate the service and disabled more than 150 additional domains tied to its supporting infrastructure. In the United Kingdom, the Metropolitan Police Service’s cybercrime team arrested two men on suspicion of offenses connected with the alleged operation of EvilTokens,” the company said.

How the scam actually worked

According to Microsoft, what set EvilTokens apart was the AI-style chatbot sitting at the heart of the operation. The chatbot could analyse a victim’s inbox and help criminals pinpoint trusted relationships, payment approval authority, sensitive job responsibilities and other circumstances where fraud was most likely to succeed. It could even go a step further, recommending specific fraud strategies and drafting messages impersonating trusted contacts to manipulate victims into taking action.The account compromises were carried out through a legitimate OAuth authentication process known as device code authentication. This method was originally designed for devices like smart TVs, essentially anything lacking a standard login interface. In this setup, the device being signed into displays a code, and the user is instructed to enter that code into a browser on a separate device, which then gets authenticated.EvilTokens gave its customers a platform capable of automating the mass sending of spam emails. Anyone who clicked on a malicious link or attachment inside these emails would be redirected to a webpage running a hidden automation script, which interacted in real time with the victim’s Microsoft identity provider to generate a device code that would enrol a device belonging to the attacker.The victim would then see this device code onscreen, along with instructions telling them to copy it and enter it into Microsoft’s official device login portal. Behind the scenes, complex backend operations allowed the hackers slip past traditional signature- or pattern-based security detection systems. This technique powered the entire attack chain, from generating dynamic device codes all the way through to actions taken after an account was compromised.Microsoft said EvilTokens marks a significant shift in how mass account compromises, and everything that follows them, now unfold.



Source link

Author

admin

Follow Me
Other Articles
Previous

Delaware Beach Homes: Delaware beach towns see population surge as tax savings draw new residents

Next

As iPhone upgrades get costlier, how trade-ins and financing options are ‘changing’

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

After media, Zinedine Zidane BANS haircuts at Clairefontaine as France manager blocks hairdressers from camp | International Sports News

After media, Zinedine Zidane BANS haircuts at Clairefontaine as France manager blocks hairdressers from camp | International Sports News

September 25, 2026
Anthony Joshua reveals heartbreaking struggle ahead of long-awaited Tyson Fury showdown on December 11 | International Sports News

Anthony Joshua reveals heartbreaking struggle ahead of long-awaited Tyson Fury showdown on December 11 | International Sports News

September 25, 2026
Delhi high court orders removal of deepfake pics showing woman with PM Modi; notice issued to CJP leaders, cops | Delhi News

Delhi high court orders removal of deepfake pics showing woman with PM Modi; notice issued to CJP leaders, cops | Delhi News

September 25, 2026
Abhijeet Dipke: ‘You will be handed a few wins’: Amid SIR row, CJP founder Abhijeet Dipke asks opposition parties to stop contesting in ‘rigged’ polls | Delhi News

Abhijeet Dipke: ‘You will be handed a few wins’: Amid SIR row, CJP founder Abhijeet Dipke asks opposition parties to stop contesting in ‘rigged’ polls | Delhi News

September 25, 2026

About Us

We love WordPress and are here to provide you with professional-looking WordPress themes so you can take your website one step ahead. We focus on simplicity, elegant design, and clean code.

TG: Ads

About Us

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.

We love WordPress and we are here to provide you with professional-looking WordPress themes so that you can take your website one step ahead. We focus on simplicity, elegant design, and clean code.

Category

  • ଦେଶ ବିଦେଶ
  • ଜିଲ୍ଲା
  • ରାଜ୍ୟ
  • ଓଡିଶା
  • ରାଜନୀତି
  • ଅର୍ଥନୀତି
  • ବାଣିଜ୍ୟ
  • ଅପରାଧ
  • ଖେଳ

Useful Links

  • ରାଜ୍ୟ
  • ଦେଶ ବିଦେଶ
  • ଜିଲ୍ଲା
  • ଓଡିଶା
  • ରାଜନୀତି
  • ଅର୍ଥନୀତି
  • ବାଣିଜ୍ୟ
  • ଅପରାଧ
  • ଖେଳ
  • Privacy Policy
  • Contact Us
  • About Us
  • Terms of Use
Copyright 2026 — Koshal Sambad. All rights reserved. SSWPL