ARToken PhaaS Platform Exposes Advanced Microsoft 365 Phishing Toolkit

Cisco Talos researchers discover a new phishing-as-a-service platform called ARToken that operates as an affiliate of the EvilTokens phishing ecosystem. The platform features a React-based management panel exposing over 80 API endpoints, revealing capabilities that extend far beyond typical phishing toolkits. Attackers use ARToken to steal Microsoft 365 authentication tokens, establish persistent access through Primary Refresh Tokens, and freely access Outlook mailboxes, SharePoint sites, and OneDrive files.

Multiple technical similarities confirm ARToken's connection to the EvilTokens platform documented earlier this year. The toolkit relies on Microsoft's OAuth 2.0 Device Authorization Grant flow, tricking victims into entering legitimate device codes on Microsoft's official login page. This device code phishing technique causes Microsoft to issue authentication tokens directly to attackers, effectively bypassing multi-factor authentication protections because victims authenticate through Microsoft's own infrastructure.

ARToken operates as a multi-tenant service where affiliates manage individual campaigns through dedicated workspaces, automating many aspects of business email compromise operations. The platform deploys phishing infrastructure through Cloudflare Workers and shares identical API calls with EvilTokens, including the same primary refresh token endpoints for setting up, refreshing, and renewing access even after tokens expire. The discovery highlights the growing sophistication of phishing services available to cybercriminals targeting Microsoft 365 environments.

Read More at the original source →