AI-Built Phishing Kits Are Industrializing Business Email Compromise
Two AI-built Phishing-as-a-Service kits automate Microsoft 365 takeover and invoice fraud, industrializing business email compromise at scale.
Researchers uncovered two previously unseen Phishing-as-a-Service kits, TokenVault ("TokenLover") and Yakhub ("YaksaLover"), that present as legitimate SaaS products complete with pricing pages and tiered dashboards, while actually functioning as operator consoles for hijacking Microsoft 365 accounts at scale. Both show clear signs of AI-assisted development, down to code structure and leftover AI-style formatting in comments.
The kits introduce no new attack techniques - device code phishing, FOCI token pivoting, Primary Refresh Token theft, Windows Hello persistence, and MFA/CAP bypass are all previously documented, some by Microsoft's own threat intelligence team. What has changed is packaging: a single dashboard now lets low-skill operators run these attacks against dozens of victims simultaneously, complete with subscription tiers, audit logs, and campaign management.
One kit adds an AI pipeline that reads compromised mailboxes to map an organization's invoices and payment flows, enabling automated fraud. Persistence mechanisms like synthetic Windows Hello keys let attackers retain access after password resets - one kit even tracks a 'password change survival rate' metric for operators. Because phishing emails are sent from the victim's genuine, authenticated mailbox, they pass SPF/DKIM checks and are nearly indistinguishable from legitimate internal mail.
For security engineers, this marks a shift from bespoke attacks by skilled operators to commoditized, AI-accelerated BEC tooling, raising the urgency for defenses beyond password hygiene, including conditional access policies, device compliance checks, and monitoring for anomalous device registrations and token activity.
This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work