The ARToken phishing panel targets Microsoft 365 accounts
ID: a3038988-bb0d-5d0f-8087-f7241f8be5d4
STIX ID: report--a3038988-bb0d-5d0f-8087-f7241f8be5d4
Feed Name: Help Net Security
The report details Cisco Talos analysis of ARToken, an affiliate-customized build of the EvilTokens phishing platform that uses Microsoft’s OAuth device authorization flow to capture tokens (including Primary Refresh Tokens) and bypass multi-factor authentication; operators use look-alike SharePoint lures, Cloudflare Workers domains, and an exposed React management panel to automate mailbox access, file theft, and business email compromise at scale (hundreds of domains), and Talos published domains (e.g., pamconj.com) for defenders to hunt on.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
