From prompt to phish:
How AI-generated tooling is industrializing modern identity compromise
Report summary
Microsoft 365 account compromise no longer revolves solely around stolen passwords. Attackers increasingly target OAuth tokens, authenticated sessions and trusted cloud identities. This enables access methods that can bypass many of the assumptions organizations still make about phishing, multi-factor authentication and account takeover. As a result, a new generation of platforms has emerged to automate and scale large parts of the Business Email Compromise lifecycle.
This research analyses a connected set of platforms identified during a real-world investigation, including DC Broker, DC-Inbox, BoB V2, and BoB V3. Together, these applications provide an end-to-end workflow covering OAuth Device Code phishing, token management, mailbox intelligence collection, session hijacking, contact harvesting, phishing infrastructure deployment and large-scale email fraud operations. Rather than functioning as isolated utilities, the platforms appear to form a mature ecosystem that enables attackers to move from initial compromise to downstream exploitation with limited manual effort.
One of the most notable findings presented in the report is that these tools appear to have been developed using extensive AI assistance. Through source code analysis, the research identifies numerous indicators of vibe coding, including chunk-based development artefacts, AI-generated design patterns, highly consistent code structures, automated documentation styles, self-describing modules and development markers commonly associated with large language model-generated software. The evidence suggests that AI is not only being weaponized during attacks, but is increasingly helping to accelerate the creation and evolution of the tooling itself.
Particularly interesting is the discovery of Shikamaru, an AI-powered component integrated into the ecosystem. Rather than simply automating administrative tasks, Shikamaru appears to function as a dedicated intelligence layer capable of analysing stolen emails, mapping relationships, identifying high-value conversations, prioritizing targets and generating actionable intelligence for fraud and Business Email Compromise operations. The integration demonstrates how large language models can be embedded directly into criminal workflows, enabling attackers to process and exploit compromised mailboxes at a scale that would previously have required substantial human effort.
To illustrate the professionalism and operational maturity of the ecosystem, the report includes a detailed analysis of the attacker interfaces themselves. The example below shows the DC Broker Dashboard, the central Threat Actors platform used to manage compromised accounts, phishing infrastructure, token acquisition workflows, AI integrations and downstream exploitation activities. Its appearance and feature set are closer to a commercial SaaS product than a traditional phishing toolkit, proving the growing convergence between enterprise software practices and modern cybercrime.

“DC Broker Dashboard” general dashboard
The full report provides a technical breakdown of the ecosystem’s architecture, identifies detection opportunities and outlines practical hardening measures for Microsoft 365 environments. It also highlights the growing role of AI in both the creation and operation of offensive tooling, from AI-assisted software development to automated mailbox analysis and intelligence gathering. As these capabilities become easier to implement and integrate, defenders need to consider a wider range of attack paths than traditional phishing and credential theft alone.
Read the full report to explore the technical analysis of the DC Broker, DC-Inbox and BoB ecosystem, the evidence of AI-assisted development, the role of the Shikamaru intelligence component, and the defensive measures organisations can implement to detect and disrupt modern token-based compromise.



