메뉴
BL
Ars Technica • 3일 전

마이크로소프트, AI 봇으로 1.2만 계정 해킹한 사기 플랫폼 차단

IMP
8/10
핵심 요약

마이크로소프트는 구독형 사기 플랫폼 'EvilTokens'을 업계 차원에서 무력화했다고 발표했습니다. 이 플랫폼은 AI 챗봇으로 피해자의 이메일 inbox를 분석해 신뢰 관계와 송금 권한자를 찾아내고, 이를 사칭한 BEC(비즈니스 이메일 사기) 공격을 자동화하여 전 세계 1만 개 조직의 1.2만 개 계정을 탈취했습니다. 마이크로소프트는 법적 절차를 통해 50개 웹사이트와 150개 도메인을 압수했고, 영국 경시청은 용의자 2명을 체포했습니다.

번역된 본문

마이크로소프ft는 화요일, AI 챗봇을 이용해 수개월간 1만 2천 개의 마이크로소프트 계정을 탈취한 구독형 사기 플랫폼을 업계 차원에서 무력화했다고 밝혔다.

'EvilTokens'이라는 이름의 이 플랫폼은 2월 텔레그램 채널을 통해 등장했으며, 초기 가입비 1,500달러와 이후 매월 500달러의 구독료를 받았다. EvilTokens은 대량의 이메일 계정 탈취에 필요한 대부분의 단계를 간소화하는 단일 서비스를 제공했다. 이 플랫폼은 고객이 침해된 inbox를 분석하고, 가장 큰 금전적 이득을 얻을 수 있는 표적을 선정하며, 회사 직원들이 공격자가 통제하는 계좌로 송금하도록 속이는 그럴듯한 후속 이메일을 작성하는 것을 도왔다.

'날짜가 아니라 몇 분 만에'

마이크로소프트는 "EvilTokens이 사이버 범죄자들의 이메일 계정 접근을 도왔지만, 이 서비스의 핵심은 피해자의 inbox를 분석해 신뢰 관계, 결제 승인 권한, 민감한 책임 사항 등 사기가 성공할 가능성이 가장 높은 상황을 범죄자들이 식별하도록 돕는 AI형 챗봇이었다"라고 말했다. "이 플랫폼은 신뢰하는 지인을 사칭한 메시지를 작성하는 등 사기 전략까지 추천하여 범죄자가 피해자를 속여 행동하게 만들었다."

마이크로소프트에 따르면 EvilTokens 사용자들은 전 세계 1만 개 조직에 속한 1만 2천 개의 고객 계정을 탈취했으며, 가장 많은 피해는 미국에 집중되어 있다. 그다음으로 피해가 많은 국가는 캐나다, 영국, 호주, 인도, 프랑스였다. 피해 조직에는 도매 유통, 건설, 금융 서비스, 부동산, 고등교육, 의료 분야가 포함되었다. 이 무력화 작전을 지원한 보안 업체 SpyCloud이 피해자에 대한 자세한 정보를 공개했다.

마이크로소프트는 법적 절차와 파트너 네트워크를 활용해 EvilTokens 운영에 사용된 50개 웹사이트와 150개의 추가 도메인을 압수했다. 영국 경시청(스코틀랜드야드)은 이 범죄 플랫폼과 관련된 혐의로 두 남성을 체포했다.

계정 탈취는 '디바이스 코드 인증(device code authentication)'이라는 정식 OAuth 절차를 통해 이루어졌다. 이 인증 방식은 TV나 입력이 제한된 기기, 즉 일반적인 로그인 절차를 수행할 인터페이스가 없는 기기를 위해 설계된 것이다. 이 방식에서는 로그인하려는 기기가 코드를 표시하고, 사용자에게 다른 기기의 브라우저에 해당 코드를 입력하도록 안내한다. 그러면 새 기기가 인증된다.

EvilTokens은 대량의 스팸 발송을 자동화하는 플랫폼을 고객에게 제공했다. 이메일 내 악성 링크나 첨부파일을 클릭한 사용자는 숨겨진 자동화 스크립트가 실행되는 웹페이지로 이동했고, 이 스크립트는 사용자의 마이크로소프트 ID 제공자와 실시간으로 상호작용하여 공격자의 기기를 등록하는 코드를 생성했다. SpyCloud은 해당 ID 제공자가 마이크로소프트 Entra라고 확인했다. 그러면 사용자에게는 디바이스 코드가 표시되고, 이를 복사해 공식 마이크로소프트 디바이스 로그인 포털에 입력하라는 안내가 나타난다.

플랫폼 내 복잡한 백엔드 로직(Node.js)은 전통적인 시그니처 기반 또는 패턴 기반 탐지를 우회할 수 있게 했다. 이 기술을 통해 동적 디바이스 코드 생성부터 탈취 후 활동까지 전 과정이 종단간으로 작동했다.

대시보드를 통해 사용자는 표적 조직의 프로필에 맞게 유인 메시지를 조정할 수 있었다. 플랫폼은 공격 과정의 나머지 부분도 대부분 자동화했다. EvilTokens은 한 번에 5천 개의 침해된 이메일을 분석했다. AI를 활용해 이 플랫폼은 대량의 자금을 송금할 권한이 있는 직원, 이 직원들이 보고하는 관리자, 그리고 관리자나 다른 사람이 직원을 설득해 결국 공격자가 통제하는 계좌로 송금하게 만들 수 있는 그럴듯한 시나리오를 식별해냈다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span. Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. From there, the platform helped customers analyze inboxes, select targets that would provide the biggest potential payouts, and draft follow-up emails that provided realistic ruses for tricking company employees into transferring funds to attacker-controlled accounts. Minutes, not days “While EvilTokens helped cybercriminals access email accounts, at the center of the service was an AI-style chatbot that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other circumstances where fraud was most likely to succeed,” Microsoft said . “The platform could even recommend fraud strategies, including drafting messages that impersonated trusted contacts to help criminals trick victims into taking action.” Microsoft said users of EvilToken compromised 12,000 customer accounts belonging to 10,000 organizations around the world, with the highest concentration of them located in the US. Countries with the next-largest numbers were Canada, the UK, Australia, India, and France. Victim organizations included wholesale distribution, construction, financial services, real estate, higher education, and healthcare. SpyCloud, a security firm that assisted in the disruption operation, has more details about victims here . Using a legal process and a network of partners, Microsoft seized 50 websites and 150 more domains used to operate EvilTokens. The UK’s Metropolitan Police Service arrested two men on suspicion of offenses allegedly connected to the crime platform. Account compromises were achieved through a legitimate OAuth process known as device code authentication . This form of authentication is designed for TVs and input-constrained devices, meaning those that lack the interface for performing normal log-in processes. In this model, the device being signed into presents a code and instructs the user to enter it into a browser on a separate device. The new device is then authenticated. EvilTokens provided customers with a platform that automated the sending of large numbers of spam. Users who clicked on malicious links or attachments in the emails were directed to a webpage running a hidden automation script that interacts with the user’s Microsoft identity provider in real time to generate a code for enrolling a device belonging to the attacker. SpyCloud identified the ID provider as Microsoft Entra. The user would then see the device code along with instructions to copy it and enter it into the official Microsoft device login portal. Complex backend logic (Node.js) in the platform allowed the operation to bypass traditional signature- or pattern-based detection. The technique allowed the process to work end to end, from the generation of dynamic device codes to post-compromise activities. Microsoft has more on the abuse of the OAuth process here . A dashboard allowed users to tailor lures to the profiles of the organizations they targeted. The platform largely automated the rest of the attack process as well. EvilTokens analyzed 5,000 compromised emails at a time. Using AI, the platform identified employees authorized to disburse large sums of money, the managers these employees reported to, and convincing scenarios under which the manager or others could persuade the employees to transfer money into what turned out to be attacker-controlled accounts. Microsoft said that EvilTokens represents a major shift in the mass compromise and post-compromise of accounts. Normally, it took time for attackers to sift through thousands of emails to assemble the organization’s management chart, suppliers, customers, and other relationships with third parties. That burden is greatly reduced with AI-assisted tools. “For organizations, the lesson is: assume that once an inbox is compromised, criminals may understand its contents in minutes, not days,” Microsoft said. “Strong identity protections and monitoring remain essential, but organizations should also independently verify requests to change payment information, redirect funds, or approve unusual transactions through a trusted second channel.” Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 1 Comments