Threadlinqs IntelligenceStart free

Threat actorRussia (loosely associated, unconfirmed for ARToken specifically)Tracked since 2026-03

EvilTokens

Also known as:ARToken affiliate operatorsEvilTokens PhaaS

As of 2026-09-12, EvilTokens is a Russia (loosely associated, unconfirmed for ARToken specifically)-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning phishing. Also known as ARToken affiliate operators, EvilTokens PhaaS. ATT&CK coverage spans 58 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1098 (Account Manipulation), T1102 (Web Service).

Tracked threats
51 critical · 4 high
First seen
2026-03-24
Last seen
2026-09-12
ATT&CK techniques
58across 5 of 5 threats
Related CVEs
0None referenced
Attribution
Russia (loosely associated, unconfirmed for ARToken specifically)Nation or origin
Nation: Russia (loosely associated, unconfirmed for ARToken specifically) · 5 tracked threat(s) · Categories: PHISHING

Activity timeline

EvilTokens appears in 5 tracked threats between and ; the busiest month was 2026-07 with 2 reports.

ATT&CK techniques observed

58 techniques observed across 5 of 5 tracked threats · Credential Access (8), Resource Development (8), Collection (6), Stealth (formerly Defense Evasion) (6), Initial Access (5), Persistence (5)
  • T1528 Steal Application Access Token — Credential Accessobserved in 5 of 5 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 3 of 5 tracked threats
  • T1102 Web Service — Command and Controlobserved in 3 of 5 tracked threats
  • T1114 Email Collection — Collectionobserved in 3 of 5 tracked threats
  • T1187 Forced Authentication — Credential Accessobserved in 3 of 5 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 3 of 5 tracked threats
  • T1550.001 Application Access Token — Lateral Movementobserved in 3 of 5 tracked threats
  • T1566.001 Phishing: Spearphishing Attachment — Initial Accessobserved in 3 of 5 tracked threats
  • T1566.002 Spearphishing Link — Initial Accessobserved in 3 of 5 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 3 of 5 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 5 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 2 of 5 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 2 of 5 tracked threats
  • T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 5 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 2 of 5 tracked threats

Tracked threats