TRM Labs Supports Microsoft's Disruption of EvilTokens, an AI-Powered Cybercrime Service

TRM Team

TRM User Conference

Which mission will you select?

REGISTER NOW
November 2-3, 2026
Washington, D.C.
TRM Labs Supports Microsoft's Disruption of EvilTokens, an AI-Powered Cybercrime Service

Key takeaways

  • Microsoft's Digital Crimes Unit, together with Health-ISAC and a coalition of industry partners including TRM Labs, has disrupted EvilTokens — a subscription cybercrime service that used AI to turn compromised email accounts into ready-made financial fraud
  • EvilTokens packaged account takeover, AI-driven mailbox analysis, and fraud tooling into a single commercial service, lowering the expertise once needed to run business email compromise and invoice fraud at scale
  • TRM Labs supported the investigation with AI investigative capabilities and blockchain intelligence, helping map the cryptocurrency activity tied to the EvilTokens ecosystem, trace funds toward downstream cash-out points, and identify elements of the financial infrastructure criminals used to move and obfuscate funds
  • The case is an early example of how AI compresses the time between compromise and monetization — and why following the financial layer, alongside cyber infrastructure, is essential to disrupting these services

{{horizontal-line}}

Microsoft's Digital Crimes Unit has disrupted EvilTokens, an AI-powered cybercrime service that helped criminals compromise email accounts and turn that access into financial fraud. 

With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs to act against the platform and the infrastructure that supported it. 

What EvilTokens was

According to Microsoft, EvilTokens emerged in February 2026 and, within months, had been linked to more than 12,000 compromised inboxes across over 10,000 organizations worldwide. What set it apart was not how it broke into accounts, but what it did once inside. At the center of the service was an AI chatbot that could read a victim's mailbox and surface the information most useful to a fraudster, including trusted relationships, payment authorizations, vendor invoices, and the people best positioned to move money.

In other words, EvilTokens did not just help attackers write more convincing messages. It helped them decide who to target and how to exploit a relationship to extract as much money as possible. Its AI tools could summarize and translate emails, surface financial conversations, map organizational roles, and recommend targets — with preset prompts to find wire-transfer discussions, identify an organization's "money movers," locate vendor invoices, and pick the best people to impersonate.

Distributed through Telegram for a USD 1,500 setup fee and a USD 500 monthly subscription, EvilTokens packaged account compromise, mailbox analysis, target selection, and fraud preparation into a single commercial service, complete with customer support and management dashboards. It made work that once required experience across identity attacks, cloud systems, social engineering, and financial fraud available through a ready-made interface.

TRM Labs' role

TRM's role was focused on understanding the financial infrastructure behind this activity, supporting investigators with AI investigative capabilities and blockchain intelligence, helping map cryptocurrency activity associated with the EvilTokens ecosystem, trace funds toward downstream cash-out points, and identify elements of the financial infrastructure used by cybercriminals to move and obfuscate funds.

This work is part of a broader shift in how these cases get solved. As AI compresses the time between compromise and monetization, crimefighters need to compress the investigation cycle too. Investigations increasingly require intelligence across cyber infrastructure, identities, and financial flows rather than treating each as a separate problem. TRM's AI investigative capabilities help investigators bring those signals together and follow the financial relationships that connect participants across a criminal ecosystem.

Disrupting the platform

The disruption was led by Microsoft's Digital Crimes Unit and combined civil legal action with coordinated operational work across the coalition, taking down the websites, domains, and infrastructure used to run EvilTokens.

Law enforcement acted alongside it. In the United Kingdom, Microsoft worked with specialist officers from the Metropolitan Police Service's cybercrime team, sharing intelligence that enabled them to act: on September 11, 2026, officers arrested two men and seized digital devices and other items for examination. Both men have been released on police bail subject to conditions while the investigation continues.

What EvilTokens signals about cybercrime's next phase

The infrastructure behind EvilTokens has been disrupted, but the playbook it demonstrated will likely persist. Increasingly capable and accessible AI is being used to scale fraud and impersonation, and EvilTokens is an early example of how those capabilities combine with compromised accounts to accelerate financial crime.

EvilTokens ran across hosting providers, cloud services, AI tools, financial services, and multiple jurisdictions, and no single organization has visibility into all of it. Disrupting it required partners from across that ecosystem, combining cyber, identity, and financial intelligence into a single picture and taking coordinated action. As successors to EvilTokens emerge, that cross-ecosystem collaboration will be what makes disrupting them possible.

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What is EvilTokens?

EvilTokens was a subscription cybercrime service that used AI to turn compromised email accounts into financial fraud. At its center was an AI chatbot that read a victim's mailbox and surfaced the information most useful to a fraudster — trusted relationships, payment authorizations, and the people best positioned to move money. It was sold through Telegram for a USD 1,500 setup fee and a USD 500 monthly subscription.

2. How did EvilTokens use AI to commit fraud?

EvilTokens applied AI across the whole fraud process, not just one step. Once criminals had access to a mailbox, its AI tools summarized and translated emails, surfaced financial conversations, mapped organizational roles, and recommended targets — with preset prompts to find wire-transfer discussions, identify an organization's "money movers," locate vendor invoices, and pick the best people to impersonate. It then helped criminals decide how to exploit those relationships and prepare the fraud itself, packaging account compromise, mailbox analysis, target selection, and fraud preparation into a single service.

3. What was TRM Labs' role in the EvilTokens disruption?

TRM Labs focused on the financial infrastructure behind the activity, supporting investigators with AI investigative capabilities and blockchain intelligence. That work helped map the cryptocurrency activity tied to the EvilTokens ecosystem, trace funds toward downstream cash-out points, and identify elements of the financial infrastructure criminals used to move and obfuscate funds.

4. Who was involved in the EvilTokens takedown?

Microsoft's Digital Crimes Unit and Health-ISAC led the action, working with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation, and TRM Labs under authorization from the US District Court for the Eastern District of Virginia. In the United Kingdom, the Metropolitan Police Service's cybercrime team acted on shared intelligence to make arrests.

5. What does EvilTokens signal about the future of cybercrime?

EvilTokens is an early example of AI packaging the fraud process into a commercial service, and that model will likely persist even though this infrastructure has been disrupted. Because such services span hosting providers, cloud platforms, AI tools, financial services, and multiple jurisdictions, no single organization can see or disrupt all of it. Disrupting the services that follow will depend on cross-ecosystem collaboration that combines cyber, identity, and financial intelligence.

This is some text inside of a div block.
Subscribe and stay up to date with our insights
No items found.