A newly discovered phishing-as-a-service platform called ARToken PhaaS appears to operate as an affiliate of the EvilTokens phishing ecosystem, giving cybercriminals an advanced toolkit for compromising Microsoft 365 accounts. Researchers say the platform automates account takeovers, steals authentication tokens, and includes powerful tools for business email compromise (BEC) attacks.
Cisco Talos Uncovers ARToken PhaaS Platform
Researchers at Cisco Talos discovered ARToken while investigating phishing infrastructure during an incident response engagement.
Their analysis uncovered a React-based management console called ARToken Panel. The panel exposed more than 80 API endpoints, revealing a phishing platform far more sophisticated than a typical credential-stealing kit.
By reverse engineering the client-side JavaScript, Talos identified several previously undocumented features designed to automate Microsoft 365 attacks.
Platform Steals Microsoft 365 Tokens
ARToken allows attackers to steal Microsoft 365 authentication tokens after compromising victims.
The platform can also create persistent access by generating Primary Refresh Tokens (PRTs). Those tokens allow attackers to regain access even after standard authentication tokens expire.
Once attackers gain access, they can browse Outlook mailboxes, access SharePoint sites, and manage files stored in OneDrive.
Strong Evidence Links ARToken to EvilTokens
Talos found several technical similarities connecting ARToken to the EvilTokens phishing platform.
Both platforms use identical API calls for Microsoft’s Device Code authentication flow. Researchers also found the same API endpoints for creating, renewing, refreshing, and restoring Primary Refresh Tokens.
In addition, ARToken follows the same Cloudflare Workers deployment model and operates as a multi-tenant phishing service that allows affiliates to manage separate campaigns.
Device Code Phishing Continues to Grow
EvilTokens relies on Microsoft’s OAuth 2.0 Device Authorization Grant, commonly known as device code phishing.
Instead of stealing usernames and passwords directly, attackers trick victims into entering a legitimate Microsoft-issued device code on Microsoft’s official login page.
Microsoft then issues authentication tokens directly to the attacker after the victim completes the sign-in process.
Because victims authenticate through Microsoft’s legitimate infrastructure, these attacks can bypass multi-factor authentication (MFA).
ARToken Adds Advanced BEC Capabilities
Talos found that ARToken offers extensive tools for business email compromise.
Operators can read Outlook mailboxes, send emails from compromised accounts, download attachments, and search multiple mailboxes for specific keywords.
The platform also lets attackers create inbox rules that automatically forward, hide, or delete emails. Those rules help attackers maintain access while reducing the chances of detection.
In addition, ARToken provides full access to SharePoint and OneDrive. Attackers can browse, upload, download, and replace files, making data theft and malware deployment much easier.
New Features Go Beyond Previous EvilTokens Research
Talos also discovered several capabilities that previous EvilTokens research had not documented.
Attackers can import authentication tokens stolen from other sources and share compromised accounts with other operators.
The platform also supports phishing pages that automatically adjust their content based on a victim’s location.
Researchers believe these features make phishing campaigns more convincing and improve attackers’ chances of success.
Invoice Lures Target Finance Employees
Talos analyzed phishing emails linked to the platform and found that attackers primarily targeted accounts payable departments.
The emails impersonated legitimate vendors and used fake invoice themes to trick recipients into opening malicious links.
Instead of sending victims to obvious phishing websites, the emails displayed what appeared to be legitimate Microsoft SharePoint URLs. However, the links redirected victims to attacker-controlled Microsoft 365 tenants designed to capture authentication tokens.
Device Code Phishing Attacks Continue to Rise
Device code phishing has become one of the fastest-growing attack techniques targeting Microsoft 365 users.
Earlier this year, Sekoia revealed that EvilTokens operates as a commercial phishing service, charging cybercriminals a $1,500 setup fee and a $500 monthly subscription.
Push Security later reported that device code phishing attacks increased 37-fold over the past year. The company also found at least 11 phishing kits that now support the technique.
The continued growth of platforms like ARToken highlights how phishing-as-a-service operators continue expanding their tools to automate Microsoft 365 account compromise and business email fraud.


0 responses to “ARToken PhaaS Expands EvilTokens’ Microsoft 365 Phishing Toolkit With Advanced BEC Features”