Microsoft 365 Phishing Now Leaves Long-Lived Control

A single successful Microsoft 365 login can now turn into standing access, not just a stolen password. The new part is that the phishing kit is built to keep the account open after the first login through token theft and Primary Refresh Token persistence, so a reset can miss the real hold the attacker still has on mail and files. Cisco Talos found the ARToken affiliate panel exposing more than 80 APIs and client-side code that automates Microsoft 365 token theft, PRT renewal, and access to Outlook, SharePoint, and OneDrive. Talos also tied the kit to EvilTokens through shared device-code authentication calls and the same PRT-related endpoints, showing a phishing service that is built for durable account takeover. That shifts the risk from one-time credential theft to long-lived tenant abuse. If your Microsoft 365 sign-in flow or SSO trust model accepts long-lived session tokens, the account itself can become the attacker’s standing key.

Part of the PlainSec briefing for 2026-07-04

Sources