logo

Warning: ARToken Phishing Kit Automates BEC Attacks

ID: d5370783-6ab0-59e7-b01e-8b783f9be9bd

STIX ID: report--d5370783-6ab0-59e7-b01e-8b783f9be9bd

Feed Name: KnowBe4 Blog

Threat Score
78/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

Author: KnowBe4 Team

...
...

Cisco Talos reports on ARToken, a phishing-as-a-service built on the EvilTokens framework that enables targeted social-engineering and BEC operations against Microsoft 365 tenants; the panel exposes 80+ API endpoints for device-code phishing, PRT persistence, Outlook inbox read/send and rule creation, keyword monitoring, attachment access, and SharePoint exfiltration, and employs a seven-layer client-side anti-analysis system to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.