discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

ARToken PhaaS Exposes EvilTokens' Microsoft 365 Phishing Toolkit

Cisco Talos researchers discovered a new phishing-as-a-service (PhaaS) platform called ARToken, which appears to be an affiliate of the EvilTokens phishing platform. The platform allows attackers to steal Microsoft 365 authentication tokens and access various services.

By Lawrence Abrams·Jul 3·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

ARToken PhaaS Exposes EvilTokens' Microsoft 365 Phishing Toolkit
Image: bleepingcomputer.com

Researchers found a new PhaaS platform called ARToken that operates as an affiliate of the EvilTokens phishing platform. It exposes a toolkit designed to compromise Microsoft 365, including stealing authentication tokens and accessing various services like Outlook mailboxes and SharePoint sites.

Why it matters

This discovery highlights vulnerabilities in Microsoft's OAuth 2.0 Device Authorization Grant authentication workflow and underscores the need for better security measures against phishing attacks targeting Microsoft 365 users.

A new platform called ARToken helps bad guys trick people into giving them their Microsoft work account passwords so they can steal information or send fake emails.

Analysis

{"# Technical Details of ARToken Panel":"The ARToken Panel is a React-based management interface that exposes over 80 API endpoints, allowing attackers to manage their campaigns. It includes features such as stealing authentication tokens and establishing persistent access using Primary Refresh Tokens (PRTs).","# Comparison with EvilTokens":"Talos identified multiple technical similarities between the two platforms, including identical API calls for Microsoft's device code authentication flow and similar Cloudflare Workers deployment models.","# Threat Actors' Capabilities":"Threat actors can use ARToken to conduct BEC attacks by accessing Outlook mailboxes, SharePoint sites, and OneDrive files. They also have tools for monitoring multiple mailboxes simultaneously, creating inbox rules, and downloading email attachments."}

Key points

  • ARToken is a PhaaS platform that operates as an affiliate of EvilTokens
  • It allows attackers to steal authentication tokens and access various services like Outlook mailboxes and SharePoint sites
  • Threat actors can use ARToken for BEC attacks, including accessing email accounts and downloading files
The Upside

With better security measures in place, organizations can prevent attackers from using platforms like ARToken to compromise user accounts and steal sensitive data.

The Downside

If bad actors continue to use techniques like device code phishing, it could lead to more successful attacks on Microsoft 365 users, despite existing warnings about the technique's risks.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityphishingmicrosoft-365cybercrimemalware

Author

Lawrence Abrams

Intelligence analysis by

Qwen 2.5 (3B)

Published

Jul 3, 2026

Source

bleepingcomputer.com

Share

Topics

securityphishingmicrosoft-365cybercrimemalware

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.