
“EvilTokens uses tailored phishing messages to trick victims into authorizing attacker access through Microsoft’s legitimate sign-in process,” explained Jason Rivera, global field CISO at cyber range platform provider SimSpace. “Once inside, AI analyzes the mailbox to identify who controls payments, which business relationships carry trust, and which invoices or transactions present opportunities.”
Rivera, an ex-US Army threat intelligence officer, added: “It [EvilTokens] then recommends impersonation targets and helps draft fraudulent messages grounded in actual business conversations. Automated reconnaissance maps organizational permissions, while token refresh and inbox monitoring help maintain access and surface new opportunities.”
Affected organizations ranged from wholesale distribution and construction to financial services, real estate, higher education, and healthcare, according to Microsoft. Organizations across North America, the UK, France, India, and Australia were targeted through the scam.
