Skip to content
ARToken phishing panel automates Microsoft 365 compromise and BEC operations

ARToken phishing panel automates Microsoft 365 compromise and BEC operations

Feeds.4Sysops IT News July 2, 2026

The ARToken phishing-as-a-service platform has emerged as a sophisticated evolution of the EvilTokens ecosystem, specifically targeting Microsoft 365 environments. It abuses the OAuth 2.0 Device Authorization Grant, a protocol intended for keyboardless devices, to trick users into authenticating attacker sessions. This method effectively bypasses multi-factor authentication by leveraging legitimate Microsoft sign-in endpoints to capture session tokens. Source

Extracted Entities

Attack Types (1)

Malware (1)

MITRE ATT&CK (1)

Tools (1)