top of page
perceptive_background_267k.jpg

ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit

Published:

3 juli 2026 om 14:12:22

Alert date:

3 juli 2026 om 15:00:31

Source:

bleepingcomputer.com

Click to open the original link from this advisory

Identity & Access, Email & Messaging, Ransomware & Malware, Cloud & Virtualization, Web Technologies

A new phishing-as-a-service (PhaaS) platform called ARToken has been identified as an affiliate of the EvilTokens phishing platform. The platform provides researchers insight into a sophisticated toolkit specifically designed to compromise Microsoft 365 accounts. ARToken appears to extend the capabilities of EvilTokens, enabling threat actors to conduct large-scale phishing campaigns targeting Microsoft 365 users. The PhaaS model lowers the technical barrier for cybercriminals by offering ready-made phishing infrastructure and tools. This discovery highlights the growing ecosystem of phishing-as-a-service platforms that target enterprise cloud identity systems. The exposure of ARToken's operations provides valuable intelligence into the tactics, techniques, and procedures used by EvilTokens affiliates.

Technical details

ARToken is a phishing-as-a-service (PhaaS) platform identified as an affiliate of the EvilTokens phishing platform, discovered by Cisco Talos during an incident response engagement. It features a React-based management panel ('ARToken Panel') with over 80 exposed API endpoints. Key technical characteristics include: (1) Device Code Phishing: Exploits Microsoft's OAuth 2.0 Device Authorization Grant flow — victims are tricked into entering a legitimate Microsoft-issued device code on Microsoft's official device login page, causing Microsoft to issue authentication tokens directly to the attacker, bypassing MFA. (2) Token Theft & Persistence: Steals Microsoft 365 authentication tokens, elevates access to Primary Refresh Tokens (PRTs), and can refresh, renew, and reacquire PRTs even after expiry. Uses identical API calls as EvilTokens including POST /api/device/start. (3) Cloudflare Workers Deployment: Deploys phishing infrastructure via Cloudflare Workers. (4) Multi-Tenant Architecture: Affiliates manage campaigns through dedicated workspaces. (5) BEC Capabilities: Full Outlook mailbox access, sending emails as compromised users, creating inbox rules to forward/hide/delete messages, monitoring multiple mailboxes for keywords, downloading attachments. (6) File System Access: Browse, upload, download, and manage SharePoint and OneDrive files for data theft and malware delivery. (7) Additional Features: Load tokens from external sources, share compromised account access, geo-targeted phishing pages that update content based on victim location. (8) AI Integration (EvilTokens): AI-driven workflow to score financial exposure of harvested mailboxes, AI/LLM-based BEC campaign drafting, and translation of stolen emails. (9) Phishing Emails: Impersonate legitimate vendors with invoice-themed lures targeting accounts payable staff, displaying fake SharePoint addresses while directing victims to attacker-controlled Microsoft 365 look-alike tenants. Device code phishing attacks surged 37-fold over the past year with at least 11 kits now offering this technique. EvilTokens is sold for a $1,500 setup fee and $500/month subscription.

Mitigation steps:

1. Disable or restrict Microsoft's OAuth 2.0 Device Authorization Grant (device code flow) for users who do not require it via Conditional Access policies in Microsoft Entra. 2. Monitor for anomalous device code authentication requests and token issuance activity in Microsoft Entra sign-in logs. 3. Implement Conditional Access policies requiring compliant or hybrid Azure AD-joined devices to reduce PRT abuse risk. 4. Enable and monitor Microsoft Entra ID Protection alerts for suspicious token usage and sign-in anomalies. 5. Educate users, especially accounts payable staff, about invoice-themed phishing lures and the device code phishing technique. 6. Monitor mailboxes for unauthorized inbox rules (forwarding, hiding, or deleting messages) that may indicate compromise. 7. Audit SharePoint and OneDrive access logs for unusual file access, upload, or download activity. 8. Implement behavioral AI-based email security solutions to detect and block device code phishing attempts that bypass traditional MFA. 9. Hunt for Cloudflare Workers-hosted phishing infrastructure in email gateway and proxy logs. 10. Revoke suspicious OAuth tokens and Primary Refresh Tokens for potentially compromised accounts immediately. 11. Block or alert on use of known EvilTokens/ARToken API patterns (e.g., POST /api/device/start) at the network perimeter.

Affected products:

Microsoft 365
Microsoft Outlook
Microsoft SharePoint
Microsoft OneDrive
Microsoft Entra (Azure AD)
Microsoft OAuth 2.0 Device Authorization Grant flow

Related links:

Related CVE's:

Related threat actors:

IOC's:

API endpoint: POST /api/device/start (device code authentication flow), Primary Refresh Token (PRT) API endpoints for setup, refresh, renew, and reacquire, React-based management panel: ARToken Panel, Phishing infrastructure deployed via Cloudflare Workers, Invoice-themed phishing emails impersonating vendors targeting accounts payable, Fake SharePoint URLs redirecting to attacker-controlled Microsoft 365 tenant look-alikes

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page