ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate) — Threadlinqs Intelligence
As of 2026-07-01, ARToken: Business Email Compromise-as-a-Service Platform Targeting Microsoft 365 (Cisco Talos / EvilTokens Affiliate) is a high-severity phishing threat attributed to EvilTokens (Russia (loosely associated, unconfirmed for ARToken specifically)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1036 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: EvilTokens · Russia (loosely associated, unconfirmed for ARToken specifically) · FINANCIAL
Cisco Talos disclosed ARToken, a fully-featured Phishing-as-a-Service (PhaaS) operator panel that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform. ARToken
On July 1, 2026, Cisco Talos published research on ARToken, an affiliate operator panel of the EvilTokens Phishing-as-a-Service (PhaaS) operation. Where EvilTokens (first documented by Sekoia in March 2026 and corroborated by Microsoft in April 2026) provided a turnkey Microsoft device-code phishing kit for OAuth 2.0 Device Authorization Grant (RFC 8628) abuse, ARToken is a complete downstream BEC operations environment built on top of stolen tokens. The React-based ARToken dashboard exposes over 80 documented API endpoints covering device-code initiation (/api/device/start, hardcoded operator UUID 84eb384d-cd3e-4c90-a283-c960ce557913), Primary Refresh Token lifecycle management (/prt/setup, /prt/refresh, /prt/renew, /prt/reacquire, /prt/cookie), full Outlook inbox read/send with BCC batching, inbox rule creation for forwarding and evidence suppression, SharePoint/OneDrive browse-upload-download-permission operations, cross-account keyword monitoring ('Box Monitor'), token import from external sources, and automated Cloudflare Worker phishing-page deployment. A standalone Windows desktop application, ARTBrowser, allows operators to browse hijacked sessions directly. The kit layers a seven-stage client-side anti-analysis system (headless-browser User-Agent blocking, navigator.webdriver checks, browser fingerprinting, window-dimension analysis, mouse/touch interaction telemetry, an 800ms timing gate, and non-linear movement-pattern validation) atop XOR-encrypted payloads (16-byte key), a materially more sophisticated evasion approach than the server-side X-Antibot-Token (SHA-256 of secret + Unix timestamp + '_antibot', 5-minute validity window) used by the base EvilTokens kit. Operators lure accounts-payable, finance, HR, and logistics staff at real vendor relationships with outstanding-invoice and urgency-themed emails, in several documented cases spoofing legitimate vendor contacts to reach real AP recipients at victim organizations including public-sector and life-sciences entities. Phishing infrastructure is fronted through Cloudflare Workers (observed patterns include clear90489058903-document.workers[.]dev and UUID-prefixed {uuid}-docviewer.workers[.]dev, as well as the wider EvilTokens adobe-[a-z0-9]{3}.[a-z0-9-]{3,}-s-account.workers.dev pattern), with a dedicated management panel (dashboard-bl.pamconj[.]com) and C2 API (spx.pamconj[.]com). EvilTokens itself has been tracked hitting 340+ organizations across the US, Canada, Australia, New Zealand, Germany, France, India, Switzerland, and the UAE since first detection on February 19, 2026, using multi-hop redirect chains that abuse Railway.com-hosted infrastructure, Vercel, compromised legitimate sites, and even redirects through security-vendor domains (Cisco, Trend Micro, Mimecast) to evade reputation-based filtering. Threat activity has been loosely associated with Russia-aligned clusters including Storm-2372, APT29, UTA0304, UTA0307, and UNK_AcademicFlare, alongside a related independent kit, Kali365, flagged by the FBI IC3 in a May 21, 2026 PSA (I-052126-PSA) using the identical device-code phishing mechanic. The EvilTokens/ARToken ecosystem is commercialized: EvilTokens core access sells for $1,500 one-time plus $500/month, a standalone Portal Browser for $500 lifetime, and anti-bot page add-ons distributed via a dedicated Telegram bot with 24/7 operator support. Because the initial authentication step occurs on Microsoft's own legitimate devicelogin page, the technique evades most conventional credential-phishing detections, and captured Primary Refresh Tokens persist attacker access across victim password resets, requiring explicit device-code-flow conditional access blocks and refresh-token revocation for remediation.
Weaknesses (CWE)
CWE-287, CWE-294, CWE-346
Target sectors: finance, human resources, logistics, accounts-payable, life sciences, public sector, construction, non-profit organisation, real estate, manufacturing, financial services, health
Target regions: united states of america, canada, australia, new zealand, germany, france, india, switzerland, united arab emirates
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589.002, T1583.006, T1587.001, T1588.002, T1566.002, T1566.001, T1078.004, T1204.001, T1098.001, T1098.005