Threats · 73 days ago
A single successful Microsoft 365 login can now turn into standing access, not just a stolen password. The new part is that the phishing kit is built to keep the account open after the first login through token theft and Primary Refresh Token persistence, so a reset can miss the real hold the attacker still has on mail and files.
Cisco Talos found the ARToken affiliate panel exposing more than 80 APIs and client-side code that automates Microsoft 365 token theft, PRT renewal, and access to Outlook, SharePoint, and OneDrive. Talos also tied the kit to EvilTokens through shared device-code authentication calls and the same PRT-related endpoints, showing a phishing service that is built for durable account takeover.
That shifts the risk from one-time credential theft to long-lived tenant abuse. If your Microsoft 365 sign-in flow or SSO trust model accepts long-lived session tokens, the account itself can become the attacker’s standing key.
4 sources covering this story
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
A new phishing-as-a-service (PhaaS) platform dubbed
The ARToken phishing panel targets Microsoft 365 accounts - Help Net Security
Cisco Talos found the ARToken phishing panel, an EvilTokens affiliate build targeting Microsoft 365 with 80+ API endpoints and MFA bypass.
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365.
This phishing kit looks more like BEC-as-a-service
Cisco Talos has uncovered ARToken, a full-fledged "BEC-as-a-service" platform linked to EvilTokens that uses sophisticated AI lures to hijack corporate accounts.
Part of the PlainSec briefing for 2026-07-04