ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos exposes ARToken, a phishing-as-a-service panel with 80+ API endpoints purpose-built for device-code phishing, token persistence, and BEC against Microsoft 365 — industrialising an attack chain that bypasses MFA.
Summary written by editorial AI · Source link below
Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.
Editorial Analysis
Device-code phishing bypasses conventional MFA, and a mature PaaS panel dramatically lowers the skill barrier — expect a surge in BEC incidents targeting M365 tenants across Europe.
Implement conditional access policies that block device-code authentication flows where not operationally required, and monitor for anomalous Primary Refresh Token usage.
A commercialised phishing platform specifically targets Microsoft 365 in ways that circumvent multi-factor authentication, raising BEC risk enterprise-wide.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Cisco Talos in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul