Normal view
Microsoft: Recent Windows updates cause desktop loading issues
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft fixes bug that broke Windows File History backup feature
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek.
Microsoft: September Windows updates break Always On VPN connections
-
CyberScoop
- Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday.
The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565βs campaigns differed from those attacks by using multiple fake websites to deceive victims.
Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.
βThis seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,β Volexity wrote in the blog post. βThe activity reported so far reflects only two organizationsβ observations; the full scope and impact are likely far broader.β
The vulnerabilities include: CVE-2026-85046 and CVE-2026-87491, remote-code execution defects in the JavaScript engine for Chromium-based browsers; and CVE-2026-85880, a privilege-escalation zero-day that Microsoft disclosed Sept. 8 in Windows Advanced Local Procedure Call.Β
Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window.Β
Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.
Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as βCLEANGULP.β Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.Β
βUTA0565βs use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,β researchers wrote. βUsing real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.β
The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.
-
CyberScoop
- Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday.
Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used for operations and disabled more than 175 domains linked to EvilTokensβ supporting infrastructure.Β
EvilTokens, launched in February 2026, was βa powerful cybercrime platform that used AI at every step of the attack chain β from compromising email accounts to designing intricate roadmaps for financial fraud and scams,β Steven Masada, associate general counsel and general manager of Microsoftβs Digital Crimes Unit, wrote in a blog post.
About 1,000 cybercriminals used EvilTokens over the course of its operation, a Microsoft spokesperson told CyberScoop.
The service was centered on an AI-style chatbot that cybercriminals used to analyze victimsβ inboxes, identify trusted relationships, payment authorizations and other sensitive details that could facilitate fraud.
βAI was not simply helping attackers write more convincing messages. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible,β Masada wrote.Β
EvilTokens was one of the most widely used phishing-as-a-service platforms prior to its takedown. It facilitated business-email compromise campaigns by stealing session tokens that allowed cybercriminals to sift through a victimβs inbox and maintain persistent access.
βWe cannot estimate the total fraud attributable to all EvilTokens activity. However, we were able to correlate at least 13 complaints filed with the FBIβs Internet Crime Complaint Center to EvilTokens-linked activity, representing approximately $1.7 million in reported losses,β a Microsoft spokesperson said. βBecause many incidents go unreported and not all victims can be definitively linked to specific campaigns, we believe this is a conservative estimate.β
Victims of EvilTokens were largely concentrated in the United States, Canada, the United Kingdom, Australia, India and France, according to Microsoft. SpyCloud, which supported the takedown, identified compromised email domains spanning 79 countries.
Microsoft said it also identified two men behind EvilTokens β Felix Utomi and Waidi Segun Adams β and attributes the development and support of the platform to Storm-2992, a threat actor unaffiliated with any other known cybercrime groups.
The United Kingdomβs Metropolitan Police acted on that information Sept. 18 when it served warrants in the greater London area, arrested the men accused of making articles for use in fraud and money laundering and seized their digital devices.
The Metropolitan Police said it received information from Microsoft about EvilTokensβ administrators in August. Utomi and Adams were released on bail as the investigation continues.Β
βThe two primary operators identified in our investigation were residing in the U.K.,β a spokesperson for Microsoft told CyberScoop.Β βWhile our investigation focused on those individuals, we believe others may have supported the operation in various capacities.β
Microsoftβs legal filing in the U.S. District Court for the Eastern District of Virginia refers to five additional unidentified people allegedly acting as support personnel and users.
Microsoft and others involved in the EvilTokens takedown, including Health-ISAC, Cloudflare, OpenAI, Shadowserver and TRM Labs, didnβt fully quantify how much fraud the service enabled, but it gained popularity quickly among cybercriminals and was lucrative for its operators.
Coinbase, which also aided the investigation into EvilTokens, said it traced about $1.1 million in revenue for EvilTokens from its paying customers. The virtual currency companyβs threat researchers found more than 1,000 deposits to EvilTokens from more than 700 distinct addresses through June 2026.Β
Operators sold access to the service through Telegram for a $1,500 initiation fee and a recurring $500 subscription. EvilTokens significantly lowered the barrier to entry for cybercriminals by including specialized tools for identity attacks, cloud systems, social engineering and financial fraud in a single interface.
The service allowed cybercriminals to map organizational structure and permissions in Microsoft Graph, which enabled lateral movement, researchers said. With active tokens gained through a collection of highly-targeted phishing lures, cybercriminals consistently bypassed multi-factor authentication, email gateways and endpoint security tools.
Microsoft said the platformβs creators developed portions of the platform with AI and it uncovered capabilities from multiple AI models.Β
βIt packaged much of the criminal process into a commercially run service, complete with subscription pricing, customer support, management dashboards and tools designed to move customers from account access toward financial exploitation,β Masada added.
The companies and organizations involved in the globally-coordinated takedown identified and notified potential victims, shared indicators of compromise and shared intelligence with law enforcement about EvilTokenβs operators and some of its customers.
Experts advised organizations and employees to treat unsolicited device codes as a red flag, assume compromised accounts are fully cataloged in minutes, and independently verify requests to change payment information or redirect funds.
βThe infrastructure supporting EvilTokens has been disrupted, but the model it demonstrated will not disappear with it,β Masada warned.
The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud appeared first on CyberScoop.
Microsoft Helps Take Down Massive Automated, AI-Powered Phishing-as-a-Service Platform
Read more of this story at Slashdot.
New Windows Defender zero-day blocks Microsoft antivirus updates
Microsoft to retire Microsoft 365 Companion apps in December
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft: September updates break File History backup feature
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
Microsoft Teams will let admins block custom file extensions
Microsoft fixes broken copy and paste for Excel 2016 users
Rust is Now a 'Tier One' Language at Microsoft
Read more of this story at Slashdot.