Bottom line: Microsoft's automated threat detection system effectively countered EvilTokens' AI-powered phishing platform, neutralizing its attacks.
What's happening: EvilTokens, a cybercrime platform, leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. In July 2022, the platform used an AI-powered attack tool to target US-based organizations, resulting in 47 reported phishing attempts. Microsoft's threat detection system identified the AI-driven attacks, flagging them for review.
What to do: Security teams should review their detection systems to ensure they can identify AI-driven phishing attacks, and consider implementing AI-powered threat detection tools to stay ahead of emerging threats.