Microsoft said on 22 September that it disrupted EvilTokens, a subscription platform BleepingComputer also ties to more than 12,000 Microsoft accounts at over 10,000 organizations. Ars Technica reports an opening fee of 1,500 dollars and a later monthly fee of 500 dollars, inbox scanning that drafts messages in a trusted contact's voice, and sign-in through the device code built for televisions. Microsoft says it seized 50 websites and 150 domains. London police arrested two men. That is not a conviction.
Artificial Intelligence··Morning
A paid inbox tool goes dark
Microsoft said on 22 September that it disrupted a subscription platform called EvilTokens. BleepingComputer reports the same disruption, led by Microsoft's Digital Crimes Unit, and the same scale: more than 12,000 Microsoft accounts at over 10,000 organizations. Ars Technica says the largest share of those accounts was in the United States.[1], [2]
What the subscription sold
Ars Technica, reporting Microsoft's account, describes an initial fee of 1,500 dollars and a later monthly fee of 500 dollars. The tool scans an inbox, picks people authorized to pay, and drafts messages that imitate a trusted contact. The takeover uses the device-code sign-in built for televisions. SpyCloud took part in the operation.[1]
Sites seized, two men arrested
Microsoft said it seized 50 websites and 150 domains, Ars Technica reports. London's Metropolitan Police arrested two men on suspicion. That is not a conviction. BleepingComputer's account of the disruption does not add a court outcome either. SpyCloud's role, in the Ars Technica account, was participation in the operation rather than a separate prosecution.[1], [2]