Consumer Protection Tuesday: Taking Down Evil Tokens

โดย Leah Bressackอ่าน 4 นาที
Consumer Protection Tuesday: How to Spring Clean Your Digital Life

What is EvilTokens?

EvilTokens was a turnkey phishing-as-a-service platform operated through Telegram bots. For a fee, anyone could run sophisticated BEC campaigns using its access weaponization, email harvesting, reconnaissance tooling, built-in webmail interface, and AI-powered automation. At the time of the takedown, its operator was signaling plans to expand the kit to target Gmail and Okta accounts.

What set EvilTokens apart wasn't just its scale, it was how it used AI. Once inside a mailbox, the platform provided attackers with an AI-powered analyst that mapped trusted relationships, identified who controlled payments, and flagged where fraud was most likely to succeed. This collapsed a process that once required hours of manual inbox sifting into a near-instant automated targeting system, putting sophisticated fraud capabilities in the hands of far less skilled criminals. Investigators also found evidence that parts of the platform were "vibe coded," meaning AI was used to build the criminal tools themselves, further lowering the barrier to entry for would-be fraudsters.

How the attack worked

EvilTokens exploited Microsoft's device code login flow, a legitimate sign-in feature, and turned it into an MFA bypass:

  1. Victims received convincing, AI-generated emails styled as invoices, shared documents, or voicemail notifications, with malicious links embedded.

  2. The links led to fake Microsoft or DocuSign pages displaying a code and instructing victims to enter it on Microsoft's real website to "verify their identity." Doing so authorized the attacker's session. Because authentication happened on Microsoft's legitimate infrastructure, MFA was bypassed entirely.

  3. The attacker's access tokens survived password resets. Attackers registered devices in Entra ID for persistent access, created hidden inbox rules to suppress alerts and delete evidence, then impersonated finance staff, vendors, or executives inside live payment threads to redirect payments, including cryptocurrency.

The real-world cost

In just a few months, EvilTokens gained traction across the cybercrime landscape, with the highest concentrations of victim activity observed in the United States, Canada, the United Kingdom, Australia, India, and France. Affected organizations spanned industries including wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

Coinbase customers were among those harmed. Although no Coinbase accounts or credentials were compromised, customers were socially engineered through manipulated emails into sending cryptocurrency to addresses owned by scammers. Compromised inboxes are increasingly the first step in crypto theft, which is why this case mattered to us even though the phishing never targeted Coinbase credentials directly.

How Coinbase helped take it down

This takedown was a coordinated effort across technology companies, security organizations, financial institutions, and law enforcement, including Microsoft, Health-ISAC, Cloudflare, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs. Coinbase's contribution centered on what we do best: following the money.

EvilTokens sold its phishing kits for cryptocurrency, routing revenue through payment processors before consolidating funds on the Tron blockchain. That financial trail is where our Global Intelligence team went to work:

  • Mapped the money. We traced approximately $1.1 million in platform revenue across four Tron addresses between October 2025 and June 2026, identified more than 1,000 deposits to EvilTokens from over 700 distinct addresses across the crypto ecosystem, and mapped full fund flows from payments to EvilTokens through to final cash-out destinations.

  • Identified the operators. Combining test transaction data, merchant records, device data, and open source information, we helped attribute the platform to the operators and referred them to the Metropolitan Police.  On September 11, 2026, officers arrested them, seizing digital devices and other items for examination.

  • Identified the customers. When we found purchasers of EvilTokens on our platform, we investigated them and referred them to law enforcement.

  • Powered the disruption. Our evidence supported Microsoft's civil case, which resulted in the seizure of 50 websites and the disabling of more than 175 domains tied to EvilTokens' infrastructure. We'll continue to work with private industry and law enforcement as part of the broader disruption effort.

How to protect yourself

  • Treat unsolicited device codes as a red flag. Only enter a code you initiated yourself. No legitimate service will ask you to "verify your identity" by entering a code it sent you.

  • Verify payment changes out of band. If a vendor or executive changes payment instructions, especially to a new bank account or crypto address, confirm through a known phone number before sending funds.

  • Use phishing-resistant authentication such as passkeys or hardware security keys.

  • For organizations: audit Entra ID for unauthorized device registrations and suspicious inbox rules, and consider restricting device code flows via Conditional Access.

What's next

The infrastructure is down and we're supporting the Metropolitan Police and other international law enforcement agencies as criminal investigations proceed. We'll keep hunting the networks that enable these crimes, on or off our platform.

If you build, sell, or buy tools to defraud crypto users, we will find you.

Huge credit to the Coinbase Global Intelligence team, whose rigor and persistence made this outcome possible.

เรื่องล่าสุด

Disclaimers: Derivatives trading through the Coinbase Advanced platform is offered to eligible EEA customers by Coinbase Financial Services Europe Ltd. (CySEC License 374/19). In order to access derivatives, customers will need to pass through our standard assessment checks to determine their eligibility and suitability for this product.