Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

微软捣毁一个利用人工智能辅助、导致 1.2 万个账户被入侵的诈骗平台

Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span. 微软周二表示,其主导了一次全行业的联合行动,捣毁了一个基于订阅制的诈骗平台。该平台利用人工智能聊天机器人,在短短几个月内入侵了 1.2 万个微软账户。

Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts. 该平台名为“EvilTokens”,于今年 2 月通过 Telegram 频道推出,初始费用为 1500 美元,此后每月收取 500 美元的续费。EvilTokens 提供了一站式服务,简化了大规模入侵电子邮件账户所需的大部分步骤。此外,该平台还能帮助客户分析收件箱、筛选出潜在收益最大的目标,并起草后续邮件,通过逼真的骗局诱导公司员工将资金转入攻击者控制的账户。

Minutes, not days 只需几分钟,而非几天

“While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said. “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.” 微软表示:“虽然 EvilTokens 帮助网络犯罪分子获取了电子邮件账户的访问权限,但该服务的核心是一个人工智能聊天机器人。它能够分析受害者的收件箱,帮助犯罪分子识别受信任的关系、支付授权、敏感职责以及其他最容易实施诈骗的情况。该平台甚至能推荐诈骗策略,包括起草冒充受信任联系人的信息,诱导受害者采取行动。”

Microsoft said users of EvilToken compromised 12,000 customer accounts belonging to 10,000 organizations around the world, with the highest concentration of them located in the US. Countries with the next-largest numbers were Canada, the UK, Australia, India, and France. Victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm that assisted in the disruption operation, has more details about victims here. 微软称,EvilTokens 的用户入侵了全球 1 万家机构的 1.2 万个客户账户,其中美国受影响最严重。受影响数量紧随其后的国家包括加拿大、英国、澳大利亚、印度和法国。受害机构涵盖批发分销、建筑、金融服务、房地产、高等教育和医疗保健等行业。协助此次捣毁行动的安全公司 SpyCloud 在此处提供了更多关于受害者的详细信息。

Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform. 通过法律程序和合作伙伴网络,微软查封了 50 个网站和 150 多个用于运营 EvilTokens 的域名。英国伦敦警察厅逮捕了两名男子,他们涉嫌与该犯罪平台有关的违法行为。

Account compromises were achieved through a legitimate OAuth process known as device code authentication. This form of authentication is designed for TVs and input-constrained devices, meaning those that lack the interface for performing normal log-in processes. In this model, the device being signed into presents a code and instructs the user to enter it into a browser on a separate device. The new device is then authenticated. 账户入侵是通过一种合法的 OAuth 流程实现的,即“设备代码认证”。这种认证方式专为电视和输入受限设备(即缺乏执行正常登录流程界面的设备)设计。在这种模式下,被登录的设备会显示一个代码,并指示用户在另一台设备的浏览器中输入该代码,从而完成新设备的认证。

EvilTokens provided customers with a platform that automated the sending of large numbers of spam. Users who clicked on malicious links or attachments in the emails were directed to a webpage running a hidden automation script that interacts with the user’s Microsoft identity provider in real time to generate a code for enrolling a device belonging to the attacker. SpyCloud identified the ID provider as Microsoft Entra. The user would then see the device code along with instructions to copy it and enter it into the official Microsoft device login portal. EvilTokens 为客户提供了一个自动化发送大量垃圾邮件的平台。点击邮件中恶意链接或附件的用户会被引导至一个网页,该网页运行着隐藏的自动化脚本,与用户的微软身份提供商实时交互,生成一个用于注册攻击者设备的验证码。SpyCloud 确认该身份提供商为 Microsoft Entra。随后,用户会看到设备代码以及将其复制并输入到微软官方设备登录门户的说明。

Complex backend logic (Node.js) in the platform allowed the operation to bypass traditional signature- or pattern-based detection. The technique allowed the process to work end to end, from the generation of dynamic device codes to post-compromise activities. Microsoft has more on the abuse of the OAuth process here. 该平台复杂的后端逻辑(Node.js)使其能够绕过传统的基于签名或模式的检测。这种技术实现了从生成动态设备代码到入侵后活动的端到端自动化流程。微软在此处提供了更多关于滥用 OAuth 流程的信息。

A dashboard allowed users to tailor lures to the profiles of the organizations they targeted. The platform largely automated the rest of the attack process as well. EvilTokens analyzed 5,000 compromised emails at a time. Using AI, the platform identified employees authorized to disburse large sums of money, the managers these employees reported to, and convincing scenarios under which the manager or others could persuade the employees to transfer money into what turned out to be attacker-controlled accounts. 该平台提供了一个仪表板,允许用户根据目标组织的资料定制诱饵。此外,该平台还实现了其余攻击流程的大部分自动化。EvilTokens 可一次性分析 5000 封被入侵的邮件。利用人工智能,该平台能识别出有权拨付大额资金的员工、其上级经理,以及能够说服员工将资金转入攻击者控制账户的各种逼真场景。

Microsoft said that EvilTokens represents a major shift in the mass compromise and post-compromise of accounts. Normally, it took time for attackers to sift through thousands of emails to assemble the organization’s management chart, suppliers, customers, and other relationships with third parties. That burden is greatly reduced with AI-assisted tools. 微软表示,EvilTokens 代表了大规模账户入侵及入侵后活动的一次重大转变。通常情况下,攻击者需要花费大量时间筛选数千封邮件,才能梳理出组织的管理架构、供应商、客户以及与其他第三方的关系。而借助人工智能辅助工具,这一负担被大大减轻了。

“For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” Microsoft said. “Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.” 微软提醒道:“对于各机构而言,教训是:一旦收件箱被入侵,犯罪分子可能在几分钟内而非几天内就掌握其内容。强大的身份保护和监控仍然至关重要,但各机构还应通过可信的第二渠道,独立核实更改支付信息、重定向资金或批准异常交易的请求。”