ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos exposes ARToken, a phishing-as-a-service panel with 80+ API endpoints purpose-built for device-code phishing, token persistence, and BEC against Microsoft 365 — industrialising an attack chain that bypasses MFA.
Summary written by editorial AI · Source link below
Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.
Editorial Analysis
Device-code phishing bypasses conventional MFA, and a mature PaaS panel dramatically lowers the skill barrier — expect a surge in BEC incidents targeting M365 tenants across Europe.
Implement conditional access policies that block device-code authentication flows where not operationally required, and monitor for anomalous Primary Refresh Token usage.
A commercialised phishing platform specifically targets Microsoft 365 in ways that circumvent multi-factor authentication, raising BEC risk enterprise-wide.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Cisco Talos in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d