ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit

**Phishing-as-a-Service Platform Exposes Extensive Toolkit to Compromise Microsoft 365**

A disturbing new development in the world of cybercrime has been uncovered by Cisco Talos researchers. The team discovered a phishing-as-a-service (PhaaS) platform called ARToken, which appears to be an affiliate of the notorious EvilTokens phishing platform. This finding has shed light on a sophisticated toolkit designed to target Microsoft 365 users with ease.

The investigation began when researchers stumbled upon a React-based management panel called “ARToken Panel” that exposed over 80 API endpoints. By reverse engineering the client-side JavaScript code, the team uncovered capabilities that go far beyond what you’d expect from a typical phishing platform. ARToken allows attackers to steal Microsoft 365 authentication tokens, establish persistent access using Primary Refresh Tokens (PRTs), and gain access to Outlook mailboxes, SharePoint sites, and OneDrive files.

Furthermore, the platform includes tools for deploying phishing infrastructure through Cloudflare Workers and automating business email compromise (BEC) operations. This multi-tenant phishing service operates as a platform where affiliates manage their own campaigns through dedicated workspaces. The researchers found that ARToken’s API calls for Microsoft’s device code authentication flow are identical to those associated with EvilTokens attacks, suggesting a strong connection between the two platforms.

EvilTokens, which was first documented in March by Sekoia, has been linked to numerous high-profile phishing incidents. This platform focuses on exploiting Microsoft’s OAuth 2.0 Device Authorization Grant authentication workflow, known as device code phishing. Attackers trick victims into entering legitimate Microsoft-issued device codes on the official device login page, causing Microsoft to issue authentication tokens directly to the attacker instead of the victim.

The use of AI and machine learning models in EvilTokens sets it apart from other phishing kits. The platform uses an AI-driven workflow that ingests harvested mailboxes to score financial exposure, then drafts BEC campaigns using AI and language translation tools. This has made device code phishing a highly effective technique against Microsoft 365 users.

The implications of this discovery are significant. ARToken’s toolkit provides attackers with the means to compromise sensitive corporate data and conduct sophisticated BEC attacks. The ability to monitor multiple hijacked mailboxes simultaneously, load tokens from other sources, and share access to compromised accounts makes it an extremely powerful tool for cybercriminals.

For Microsoft 365 users, this news serves as a stark reminder of the importance of security awareness and best practices. It’s essential to remain vigilant against phishing attacks and implement robust multi-factor authentication protections. By staying informed about emerging threats and following established security guidelines, you can significantly reduce your risk of falling victim to these sophisticated attacks.

Ultimately, the discovery of ARToken highlights the need for continued vigilance in the face of evolving cybercrime techniques. As threat actors continue to adapt and innovate, it’s crucial that we stay one step ahead by staying informed and adopting robust security measures. By doing so, we can mitigate the impact of these attacks and protect our sensitive data from falling into the wrong hands.


Source: Bleeping Computer — 2026-07-03