Trusted Design

Inside an affiliate panel targeting Microsoft 365

概要

Cisco Talos discovered ARToken, a sophisticated phishing-as-a-service panel sharing infrastructure and operational patterns with the EvilTokens platform. The panel exposes over 80 API endpoints enabling device code phishing, Primary Refresh Token persistence, email access, business email compromise operations, and SharePoint exfiltration through a React-based dashboard. The platform deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads. ARToken abuses Microsoft's OAuth 2.0 Device Authorization Grant to bypass multi-factor authentication entirely. Analysis reveals post-compromise capabilities including token management across password resets, automated BEC operations, inbox rule manipulation for evidence suppression, cross-account keyword monitoring, and SharePoint file operations. The platform operates as multi-tenant infrastructure with subscription-based affiliate access, representing a complete operations environment rather than simple phish...

Created: 2026-07-02

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る