A sophisticated phishing platform dubbed “ARToken” has been uncovered by Cisco Talos researchers, revealing a vast toolkit designed to compromise Microsoft 365 users. The platform appears to be an affiliate of the notorious EvilTokens phishing platform, which was first exposed earlier this year.
The discovery was made while investigating phishing infrastructure used in an incident response engagement. Researchers stumbled upon a React-based management panel called “ARToken Panel,” which exposed over 80 API endpoints. Upon reverse engineering the client-side JavaScript code, Talos uncovered previously undocumented capabilities that extend far beyond what’s typically found in a phishing platform.
The ARToken platform allows attackers to steal Microsoft 365 authentication tokens, granting them persistent access through Primary Refresh Tokens (PRTs). This enables threat actors to access Outlook mailboxes, SharePoint sites, and OneDrive files. Furthermore, the platform includes tools for deploying phishing infrastructure via Cloudflare Workers and automating various aspects of business email compromise (BEC) operations.
What’s striking about ARToken is its technical similarities with EvilTokens, which suggests a strong affiliation between the two platforms. Talos researchers found identical API calls for Microsoft’s device code authentication flow, including an identical “POST /api/device/start” request associated with previous EvilTokens attacks. The platform also uses similar Cloudflare Workers deployment models and operates as a multi-tenant phishing service, where affiliates manage their own campaigns through dedicated workspaces.
EvilTokens is known for exploiting Microsoft’s OAuth 2.0 Device Authorization Grant authentication workflow, a technique called device code phishing. Victims are tricked into entering legitimate Microsoft-issued device codes on the official device login page, causing Microsoft to issue authentication tokens directly to attackers instead of the victims. This allows attacks to bypass multi-factor authentication protections and successfully compromise accounts.
Microsoft has previously warned about EvilTokens as device code phishing attacks surged dramatically, with numerous threat actors adopting this technique due to its high success rate against Microsoft 365 users. What sets EvilTokens apart is its use of AI to automate fraud, making it a particularly insidious threat.
The ARToken platform’s capabilities are staggering, allowing operators to refresh stolen tokens and elevate access to persistent primary refresh tokens (PRT). The researchers also found tools for conducting BEC attacks, including full Outlook mailbox access, the ability to send emails as compromised users, and the ability to monitor multiple mailboxes for keywords simultaneously.
Attackers can also browse, upload, download, and manage files stored in victims’ SharePoint sites and OneDrive accounts. This enables data theft and the delivery of malware for additional attacks. ARToken revealed several features not identified in previous EvilTokens research, including the ability to monitor multiple hijacked mailboxes simultaneously for specific keywords, load tokens stolen from other sources, and share access to compromised accounts.
The discovery of ARToken serves as a stark reminder of the evolving nature of phishing threats. As threat actors continue to develop new tactics and tools, it’s essential that users remain vigilant and take proactive measures to protect themselves. To mitigate these risks, users should ensure their Microsoft 365 accounts are configured with robust security settings, including multi-factor authentication and regular password changes. Additionally, implementing anti-phishing software and conducting regular security audits can help identify potential vulnerabilities and prevent attacks.
Source: Bleeping Computer — 2026-07-03