Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Il documente une plateforme Phishing-as-a-Service (PhaaS) observée pour la première fois en juillet 2026, ciblant des utilisateurs Microsoft 365. ARToken abuse du flux OAuth 2.0 device-authorization grant ... pour dérober des tokens d’accès et de rafraîchissement sans jamais afficher de fausse page de connexion.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called “ARToken” that’s built on the EvilTokens phishing platform.
T1098 — Account Manipulation (Persistence) ; Escalade Entra : réinitialisation de mots de passe, création d’utilisateurs, modification des rôles (Global Administrator)
The phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads...
The phishing lures were tailored to the targeted organization, impersonating a legitimate vendor used by the company.
The phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads, a more sophisticated evasion approach...
Adversaries consistently defeated or bypassed MFA using AitM proxies and session-token theft... T1111 Multi-Factor Authentication Interception
The phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads, a more sophisticated evasion approach...
T1534 — Internal Spearphishing (Lateral Movement) ; ARTSender : envoi de mails depuis le compte compromis via proxy
The kit includes a full-fledged business email compromise tool with the following capabilities: “Full Outlook inbox read access per compromised account ... Keyword-based monitoring across all compromised accounts simultaneously Email attachment access and download”
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Plateforme PhaaS conçue pour compromettre des comptes Microsoft 365 via le flux OAuth device code, voler des access tokens et refresh tokens, contourner les contrôles anti-phishing classiques et le MFA, puis permettre l’accès aux boîtes mail, la persistance via PRT, l’escalade Entra, la collecte d’e-mails/contacts et les opérations BEC.
Phishing-as-a-Service platform used for Microsoft 365 device code phishing. It steals Microsoft 365 authentication tokens, can elevate access to Primary Refresh Tokens for persistence, access Outlook/SharePoint/OneDrive data, create inbox rules to hide messages, monitor compromised mailboxes, and support automated BEC operations.
PhaaS framework/panel targeting Microsoft 365 that enables device code phishing via OAuth 2.0 Device Authorization Grant abuse, acquisition and persistence of Primary Refresh Tokens, BEC operations, SharePoint/OneDrive exfiltration, and multi-mailbox monitoring. It also includes anti-analysis protections and exposes a large API surface for affiliates.
A phishing panel/kit that abuses Microsoft OAuth device code flow to steal Microsoft 365 session tokens, refresh stolen tokens, access email inboxes, browse/download SharePoint and OneDrive files, create inbox rules, and escalate access into longer-lived primary refresh tokens for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.