Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Cisco Talos exposes ARToken, a phishing-as-a-service panel with 80+ API endpoints purpose-built for device-code phishing, token persistence, and BEC against Microsoft 365 — industrialising an attack chain that bypasses MFA.

Summary written by editorial AI · Source link below

Filed by Cisco Talos1 min readRead at source ↗

Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.

Editorial Analysis

Why it matters

Device-code phishing bypasses conventional MFA, and a mature PaaS panel dramatically lowers the skill barrier — expect a surge in BEC incidents targeting M365 tenants across Europe.

What to do

Implement conditional access policies that block device-code authentication flows where not operationally required, and monitor for anomalous Primary Refresh Token usage.

Board brief

A commercialised phishing platform specifically targets Microsoft 365 in ways that circumvent multi-factor authentication, raising BEC risk enterprise-wide.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Cisco Talos

External link — opens at Cisco Talos in a new tab.

§
Continue with

More from the Threat Intel Desk