ARToken Phishing-as-a-Service (EvilTokens affiliate)
First seen Jul 5, 2026 · Updated Jul 5, 2026
ARToken is a newly identified phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing ecosystem, offering attackers a turnkey toolkit to compromise Microsoft 365 accounts. The platform enables adversary-in-the-middle (AiTM) style credential and session token theft at scale, lowering the barrier to entry for large-scale enterprise account compromise.
Technical Analysis
ARToken provides an affiliate-based PhaaS infrastructure built on top of the EvilTokens toolkit, likely using reverse-proxy AiTM techniques to harvest Microsoft 365 credentials and session cookies/tokens in real time, allowing attackers to bypass MFA protections. The toolkit reportedly includes customizable phishing lures, evasion features to bypass email security gateways, and backend panels for affiliates to manage campaigns and stolen data. Stolen Microsoft 365 credentials and session tokens can be replayed to access connected cloud services, email, SharePoint, and Teams, and to pivot into other integrated SaaS applications. Organizations that integrate LLM-based agents or RAG pipelines with Microsoft 365 (e.g., Copilot, Graph API-connected agents, or automated email/document processing agents) face direct risk, since stolen OAuth tokens or session cookies could grant attackers the same API access these agents rely on, enabling data exfiltration or manipulation of agent-accessed content. Because the phishing kit targets identity and session tokens rather than a specific software vulnerability, no CVE applies, but the downstream impact on any automated system trusting an M365 identity is significant.
Affected Systems
Microsoft 365 accounts and tenants, including Exchange Online, SharePoint, Teams, and OAuth-integrated third-party/agent applications relying on Microsoft 365 identity for authentication
Indicators of Compromise
- No specific hashes, IPs, or domains disclosed in source reporting at this time; monitor for AiTM phishing infrastructure associated with EvilTokens/ARToken campaigns
Remediation Steps
- 1
Enforce phishing-resistant MFA
Deploy FIDO2/WebAuthn or certificate-based authentication for Microsoft 365 accounts to resist AiTM token theft techniques.
- 2
Monitor for anomalous token use
Enable Conditional Access with token binding, session risk detection, and continuous access evaluation (CAE) to detect and revoke stolen session tokens.
- 3
User awareness training
Train employees to recognize phishing lures mimicking Microsoft 365 login pages and report suspicious emails.
- 4
Audit OAuth app and agent permissions
Review and restrict OAuth consent grants and API scopes for AI agents, Copilot, and third-party integrations connected to Microsoft 365 to limit blast radius from token theft.
- 5
Deploy email security controls
Use advanced anti-phishing filters and URL rewriting/sandboxing capable of detecting reverse-proxy AiTM phishing pages.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.