ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Cisco Talos has identified a new phishing-as-a-service (PhaaS) platform called ARToken, which shares significant similarities with the existing EvilTokens platform operated by Sekoia and tracked by Microsoft. ARToken utilizes a React-based dashboard to provide affiliates with access to a comprehensive toolkit for device code phishing, PRT persistence, and BEC operations, including a seven-layer anti-analysis system. The discovery of ARToken highlights the ongoing evolution of sophisticated phishing campaigns and the need for robust defenses against these attacks, particularly within Microsoft 365 environments.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
