logo

The ARToken phishing panel targets Microsoft 365 accounts

ID: a3038988-bb0d-5d0f-8087-f7241f8be5d4

STIX ID: report--a3038988-bb0d-5d0f-8087-f7241f8be5d4

Feed Name: Help Net Security

Threat Score
78/100

Date Published: 2026-07-01

Date Updated: 2026-07-02

Author: Sinisa Markovic

...
...

The report details Cisco Talos analysis of ARToken, an affiliate-customized build of the EvilTokens phishing platform that uses Microsoft’s OAuth device authorization flow to capture tokens (including Primary Refresh Tokens) and bypass multi-factor authentication; operators use look-alike SharePoint lures, Cloudflare Workers domains, and an exposed React management panel to automate mailbox access, file theft, and business email compromise at scale (hundreds of domains), and Talos published domains (e.g., pamconj.com) for defenders to hunt on.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.