Researchers detailed ARToken, a phishing-as-a-service platform that abuses Microsoft 365's OAuth 2.0 device authorization flow to steal access and refresh tokens after victims enter a device code on Microsoft's legitimate sign-in page. The operation uses invoice-themed phishing emails, compromised SharePoint links, and Cloudflare Workers redirectors with anti-bot features, avoiding fake login pages and effectively bypassing MFA while reducing the visibility of traditional phishing detections. Reported infrastructure tied to the activity includes pamconj.com, corabuild.eu, multiple workers.dev domains, and several DigitalOcean IP addresses.
The reporting reflects a broader surge in device-code phishing, with CrowdStrike observing a 1,500% increase in the first half of 2026 as both criminal and state-linked actors adopt the technique. Analysts say the tradecraft has evolved from a niche method into a productized ecosystem, with services such as ARToken and Kali365 offering lure generation, dashboards, token capture, and multi-affiliate support, while post-compromise activity includes Microsoft Graph mailbox access, inbox-rule abuse, password resets, user creation, role changes, fraudulent MFA enrollment, and business email compromise. Defenders are being urged to restrict device-code sign-ins, tightly govern exceptions, and correlate device authorization events with downstream Microsoft 365 activity and new device registrations.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
ARToken, a phishing-as-a-service platform targeting Microsoft 365 users through OAuth 2.0 device authorization abuse, was first observed in July 2026. The platform uses legitimate Microsoft device login flows to steal access and refresh tokens and supports multi-affiliate operations.
Device code phishing spread from Russian state use to cybercriminal groups during 2025. Actors associated with Tycoon 2FA were identified as notable adopters.
CrowdStrike measured a 134% increase in vishing between 2024 and 2025. The reporting frames this as part of a broader shift toward social engineering methods that bypass traditional email defenses.
A Russian threat actor tracked by Microsoft as Storm-2372 began using device code phishing in an operational campaign. The activity targeted organizations across government, defense, energy, and other sectors in North America, Europe, Africa, and the Middle East.
Microsoft researcher Nestori Syynimaa published a blog post describing the technique now known as device code phishing. The article anchors this publication to October 13, 2020.
Abnormal AI published a technical report detailing ARToken's infrastructure, attack chain, token capture workflow, persistence options, and post-compromise capabilities. The report also listed domains, Cloudflare Workers hosts, and IP addresses as indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
blog.alphahunt.io
Open sourcedarkreading.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.