# EvilTokens

> As of 2026-09-12, EvilTokens is a Russia (loosely associated, unconfirmed for ARToken specifically)-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning phishing. Also known as ARToken affiliate operators, EvilTokens PhaaS. ATT&CK coverage spans 58 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1098 (Account Manipulation), T1102 (Web Service).

- **Nation:** Russia (loosely associated, unconfirmed for ARToken specifically)
- **Tracked threats:** 5
- **Categories:** PHISHING
- **Also known as:** ARToken affiliate operators, EvilTokens PhaaS
- **As of:** 2026-09-12

## ATT&CK techniques observed

58 techniques observed across 5 of 5 tracked threats. Tactics: Credential Access (8), Resource Development (8), Collection (6), Stealth (formerly Defense Evasion) (6), Initial Access (5), Persistence (5).

- [T1528](https://intel.threadlinqs.com/technique/T1528) Steal Application Access Token — Credential Access — observed in 5 of 5 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 3 of 5 tracked threats
- [T1102](https://intel.threadlinqs.com/technique/T1102) Web Service — Command and Control — observed in 3 of 5 tracked threats
- [T1114](https://intel.threadlinqs.com/technique/T1114) Email Collection — Collection — observed in 3 of 5 tracked threats
- [T1187](https://intel.threadlinqs.com/technique/T1187) Forced Authentication — Credential Access — observed in 3 of 5 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 3 of 5 tracked threats
- [T1550.001](https://intel.threadlinqs.com/technique/T1550.001) Application Access Token — Lateral Movement — observed in 3 of 5 tracked threats
- [T1566.001](https://intel.threadlinqs.com/technique/T1566.001) Phishing: Spearphishing Attachment — Initial Access — observed in 3 of 5 tracked threats
- [T1566.002](https://intel.threadlinqs.com/technique/T1566.002) Spearphishing Link — Initial Access — observed in 3 of 5 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 3 of 5 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 5 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 2 of 5 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 5 tracked threats
- [T1078.004](https://intel.threadlinqs.com/technique/T1078.004) Cloud Accounts — Initial Access — observed in 2 of 5 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 2 of 5 tracked threats

## Tracked threats

- [Device Code Phishing Surge: Tycoon2FA, EvilTokens, Kali365, Ghost Hub, and Cyb3r Add MFA-Bypass Capability](https://intel.threadlinqs.com/threat/TL-2026-2468) — HIGH
- [EvilTokens Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication with AES-GCM "Ghost Code" to Breach Finance, Tech, and Managed Security Firms](https://intel.threadlinqs.com/threat/TL-2026-1201) — HIGH
- [ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate)](https://intel.threadlinqs.com/threat/TL-2026-1036) — HIGH
- [Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365)](https://intel.threadlinqs.com/threat/TL-2026-0943) — HIGH
- [EvilTokens PhaaS Campaign Abuses Railway.com PaaS for Microsoft 365 Device Code Phishing and AiTM Token Replay](https://intel.threadlinqs.com/threat/TL-2026-0278) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/EvilTokens
