ARToken PhaaS Exposes EvilTokens' Microsoft 365 Phishing Toolkit
Cisco Talos researchers discovered a new phishing-as-a-service (PhaaS) platform called ARToken, which appears to be an affiliate of the EvilTokens phishing platform. The platform allows attackers to steal Microsoft 365 authentication tokens and access various services.
Intelligence analysis by Qwen 2.5 (3B)

Researchers found a new PhaaS platform called ARToken that operates as an affiliate of the EvilTokens phishing platform. It exposes a toolkit designed to compromise Microsoft 365, including stealing authentication tokens and accessing various services like Outlook mailboxes and SharePoint sites.
A new platform called ARToken helps bad guys trick people into giving them their Microsoft work account passwords so they can steal information or send fake emails.
Analysis
{"# Technical Details of ARToken Panel":"The ARToken Panel is a React-based management interface that exposes over 80 API endpoints, allowing attackers to manage their campaigns. It includes features such as stealing authentication tokens and establishing persistent access using Primary Refresh Tokens (PRTs).","# Comparison with EvilTokens":"Talos identified multiple technical similarities between the two platforms, including identical API calls for Microsoft's device code authentication flow and similar Cloudflare Workers deployment models.","# Threat Actors' Capabilities":"Threat actors can use ARToken to conduct BEC attacks by accessing Outlook mailboxes, SharePoint sites, and OneDrive files. They also have tools for monitoring multiple mailboxes simultaneously, creating inbox rules, and downloading email attachments."}
Key points
- ARToken is a PhaaS platform that operates as an affiliate of EvilTokens
- It allows attackers to steal authentication tokens and access various services like Outlook mailboxes and SharePoint sites
- Threat actors can use ARToken for BEC attacks, including accessing email accounts and downloading files
With better security measures in place, organizations can prevent attackers from using platforms like ARToken to compromise user accounts and steal sensitive data.
If bad actors continue to use techniques like device code phishing, it could lead to more successful attacks on Microsoft 365 users, despite existing warnings about the technique's risks.



