Overview A newly uncovered phishing‑as‑a‑service (PhaaS) platform called ARToken has revealed the inner workings of the EvilTokens phishing ecosystem — a sophisticated toolkit designed to compromise Microsoft 365 accounts through device‑code phishing and token abuse.
Researchers from Cisco Talos discovered ARToken while investigating phishing infrastructure during an incident‑response engagement. Their analysis exposed a React‑based management panel with over 80 API endpoints, offering unprecedented insight into how modern phishing operations automate account compromise and business‑email fraud.

How ARToken Works
Reverse‑engineering the client‑side JavaScript revealed capabilities far beyond typical phishing kits:
- Steal Microsoft 365 authentication tokens and establish persistent access via Primary Refresh Tokens (PRTs).
- Access Outlook, SharePoint, and OneDrive to exfiltrate emails and files.
- Deploy phishing infrastructure through Cloudflare Workers for rapid campaign setup.
- Automate business email compromise (BEC) using AI‑driven workflows and multi‑tenant management panels.
Talos found that ARToken uses the same API calls and device‑code authentication flows as EvilTokens, confirming a direct affiliate relationship.
EvilTokens and Device‑Code Phishing
EvilTokens exploits Microsoft’s OAuth 2.0 Device Authorization Grant workflow — a technique known as device‑code phishing.
Victims are tricked into entering a legitimate Microsoft‑issued device code on Microsoft’s own login page. Once entered, Microsoft issues authentication tokens directly to the attacker, allowing them to bypass multi‑factor authentication (MFA).
Key features of EvilTokens:
- AI‑driven BEC automation that scores financial exposure and drafts fraudulent emails using LLMs.
- Persistent token refresh mechanisms to maintain access even after expiration.
- Cloudflare‑based deployment model for multi‑tenant affiliate operations.
This approach has proven highly effective against Microsoft 365 users, with Push Security reporting a 37‑fold increase in device‑code phishing attacks over the past year.
ARToken’s Expanded Capabilities
Talos identified new features not previously seen in EvilTokens:
- Simultaneous mailbox monitoring for specific keywords across multiple victims.
- Shared access to compromised accounts among affiliates.
- Dynamic phishing pages that update content based on victim geolocation.
- Inbox rule manipulation to hide or delete emails and cover tracks.
Attackers can send emails as compromised users, forward messages automatically, and download attachments to fuel further fraud.
Defensive Recommendations
Organizations should take immediate steps to mitigate device‑code phishing and BEC risks:
- Restrict device‑code authentication to trusted devices only.
- Monitor token refresh activity for suspicious patterns.
- Implement behavioral AI email security to detect BEC and phishing anomalies.
- Educate employees on recognizing invoice‑themed and SharePoint‑spoofed phishing emails.
Expert in the Cloud Insight
ARToken and EvilTokens represent a new generation of AI‑enhanced phishing kits that blur the line between automation and human social engineering. By leveraging Microsoft’s legitimate authentication flows, these platforms turn trust into a weapon.
For security leaders, the lesson is clear: visibility must extend to token and device‑code activity. Traditional email filters are no longer enough — behavioral analytics and real‑time token monitoring are essential to detect and disrupt these stealthy phishing operations.
Leave a Reply