Executive Summary
In July 2026, Cisco Talos researchers uncovered 'ARToken,' a phishing-as-a-service (PhaaS) platform affiliated with the EvilTokens phishing toolkit. ARToken enables attackers to compromise Microsoft 365 accounts by stealing authentication tokens, establishing persistent access via Primary Refresh Tokens (PRTs), and accessing services like Outlook, SharePoint, and OneDrive. The platform also automates business email compromise (BEC) operations and deploys phishing infrastructure through Cloudflare Workers. (bleepingcomputer.com)
This incident highlights the evolving sophistication of phishing platforms, which now offer advanced capabilities to bypass multi-factor authentication and maintain prolonged access to compromised accounts. Organizations must enhance their security measures to counteract these advanced threats.
Why This Matters Now
The emergence of ARToken underscores the increasing sophistication of phishing-as-a-service platforms, which now offer advanced capabilities to bypass multi-factor authentication and maintain prolonged access to compromised accounts. Organizations must enhance their security measures to counteract these advanced threats.
Attack Path Analysis
Attackers initiated the compromise by sending phishing emails that tricked victims into entering device codes on legitimate Microsoft authentication pages, granting attackers access tokens. They then escalated privileges by obtaining Primary Refresh Tokens (PRTs) to maintain persistent access. Utilizing these tokens, attackers moved laterally within the Microsoft 365 environment, accessing Outlook mailboxes, SharePoint sites, and OneDrive files. Command and control were established through the continuous use of these tokens, allowing attackers to monitor and manipulate victim accounts. Data exfiltration occurred as attackers downloaded sensitive files from SharePoint and OneDrive. The impact included unauthorized access to confidential information and potential financial fraud through business email compromise (BEC) operations.
Kill Chain Progression
Initial Compromise
Description
Attackers sent phishing emails impersonating legitimate vendors, prompting victims to enter device codes on authentic Microsoft authentication pages, thereby granting attackers access tokens.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Valid Accounts
Application Layer Protocol: Web Protocols
Email Collection: Mail Client
Data from Cloud Storage
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing system and network security are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
ARToken's Microsoft 365 phishing toolkit enables business email compromise targeting accounts payable, bypassing MFA to steal authentication tokens and access financial communications.
Banking/Mortgage
Device code phishing attacks compromise Microsoft 365 accounts to conduct automated BEC fraud, with AI-driven workflows scoring financial exposure for targeted banking operations.
Computer Software/Engineering
EvilTokens PhaaS platform exploits Microsoft OAuth workflows and Cloudflare Workers deployment, compromising software companies' SharePoint sites, OneDrive files, and development communications.
Information Technology/IT
ARToken's primary refresh token persistence and mailbox monitoring capabilities enable prolonged compromise of IT organizations' Microsoft 365 infrastructure and client communication channels.
Sources
- ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkithttps://www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-microsoft-365-phishing-toolkit/Verified
- ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/Verified
- New widespread EvilTokens kit: device code phishing as-a-servicehttps://www.sekoia.com/blog/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1Verified
- Inside an AI‑enabled device code phishing campaignhttps://www.microsoft.com/en-us/security/blog/2026/04/06/ai-enabled-device-code-phishing-campaign-april-2026/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could have limited the attacker's ability to exploit compromised credentials by enforcing strict segmentation and identity-aware access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing strict access controls and segmenting sensitive resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could have limited the attacker's ability to move laterally by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could have limited the attacker's ability to maintain command and control by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could have limited the attacker's ability to exfiltrate data by enforcing strict egress policies and monitoring outbound traffic.
Aviatrix Zero Trust CNSF could have limited the overall impact by reducing the attacker's ability to access and exploit sensitive information.
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Management
- File Storage
- Collaboration Platforms
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive emails, documents, and files stored in Microsoft 365 services.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads in network traffic.
- • Enhance Threat Detection & Anomaly Response capabilities to promptly identify and mitigate suspicious behaviors indicative of compromise.



