highPhishing

ARToken Phishing-as-a-Service (EvilTokens affiliate)

First seen Jul 5, 2026 · Updated Jul 5, 2026

phishing-as-a-serviceMicrosoft 365credential-theftsession-token-theftAiTMagent-relevant

ARToken is a newly identified phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens phishing ecosystem, offering attackers a turnkey toolkit to compromise Microsoft 365 accounts. The platform enables adversary-in-the-middle (AiTM) style credential and session token theft at scale, lowering the barrier to entry for large-scale enterprise account compromise.

Technical Analysis

ARToken provides an affiliate-based PhaaS infrastructure built on top of the EvilTokens toolkit, likely using reverse-proxy AiTM techniques to harvest Microsoft 365 credentials and session cookies/tokens in real time, allowing attackers to bypass MFA protections. The toolkit reportedly includes customizable phishing lures, evasion features to bypass email security gateways, and backend panels for affiliates to manage campaigns and stolen data. Stolen Microsoft 365 credentials and session tokens can be replayed to access connected cloud services, email, SharePoint, and Teams, and to pivot into other integrated SaaS applications. Organizations that integrate LLM-based agents or RAG pipelines with Microsoft 365 (e.g., Copilot, Graph API-connected agents, or automated email/document processing agents) face direct risk, since stolen OAuth tokens or session cookies could grant attackers the same API access these agents rely on, enabling data exfiltration or manipulation of agent-accessed content. Because the phishing kit targets identity and session tokens rather than a specific software vulnerability, no CVE applies, but the downstream impact on any automated system trusting an M365 identity is significant.

Affected Systems

Microsoft 365 accounts and tenants, including Exchange Online, SharePoint, Teams, and OAuth-integrated third-party/agent applications relying on Microsoft 365 identity for authentication

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in source reporting at this time; monitor for AiTM phishing infrastructure associated with EvilTokens/ARToken campaigns

Remediation Steps

  1. 1

    Enforce phishing-resistant MFA

    Deploy FIDO2/WebAuthn or certificate-based authentication for Microsoft 365 accounts to resist AiTM token theft techniques.

  2. 2

    Monitor for anomalous token use

    Enable Conditional Access with token binding, session risk detection, and continuous access evaluation (CAE) to detect and revoke stolen session tokens.

  3. 3

    User awareness training

    Train employees to recognize phishing lures mimicking Microsoft 365 login pages and report suspicious emails.

  4. 4

    Audit OAuth app and agent permissions

    Review and restrict OAuth consent grants and API scopes for AI agents, Copilot, and third-party integrations connected to Microsoft 365 to limit blast radius from token theft.

  5. 5

    Deploy email security controls

    Use advanced anti-phishing filters and URL rewriting/sandboxing capable of detecting reverse-proxy AiTM phishing pages.

Industries Most Exposed

Financial servicesHealthcareTechnologyGovernmentRetailProfessional services

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.