Back Feeds.4Sysops ARToken phishing panel automates Microsoft 365 compromise and BEC operations
The ARToken phishing-as-a-service platform has emerged as a sophisticated evolution of the EvilTokens ecosystem, specifically targeting Microsoft 365 environments. It abuses the OAuth 2.0 Device Authorization Grant, a protocol intended for keyboardless devices, to trick users into authenticating attacker sessions. This method effectively bypasses multi-factor authentication by leveraging legitimate Microsoft sign-in endpoints to capture session tokens. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
