logo

Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access

ID: 9932a22d-9269-5c60-bd88-c53286cfd597

STIX ID: report--9932a22d-9269-5c60-bd88-c53286cfd597

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-02

Date Updated: 2026-07-03

Author: Tushar Subhra Dutta

...
...

**ARToken phishing panel** — ARToken is a phishing-as-a-service panel that abuses Microsoft’s OAuth device code flow to steal M365 access and refresh tokens (bypassing passwords and MFA), provides a feature-rich operator dashboard for mailbox and SharePoint/OneDrive access and persistence, uses multi-layer evasion (fingerprinting, human verification), and is linked to the larger EvilTokens ecosystem; the report includes IoCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.