Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access
ID: 9932a22d-9269-5c60-bd88-c53286cfd597
STIX ID: report--9932a22d-9269-5c60-bd88-c53286cfd597
Feed Name: cybersecurityNews.com
Threat Score
**ARToken phishing panel** — ARToken is a phishing-as-a-service panel that abuses Microsoft’s OAuth device code flow to steal M365 access and refresh tokens (bypassing passwords and MFA), provides a feature-rich operator dashboard for mailbox and SharePoint/OneDrive access and persistence, uses multi-layer evasion (fingerprinting, human verification), and is linked to the larger EvilTokens ecosystem; the report includes IoCs and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
