EvilTokens/ARToken Device-Code Phishing Kit Bypasses MFA to Compromise Microsoft 365 Accounts — Threadlinqs Intelligence
As of 2026-07-05, EvilTokens/ARToken Device-Code Phishing Kit Bypasses MFA to Compromise Microsoft 365 Accounts is a high-severity phishing threat attributed to EvilTokens PhaaS Operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1128 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: EvilTokens PhaaS Operators · FINANCIAL
EvilTokens is a Telegram-sold phishing-as-a-service (PhaaS) kit that abuses Microsoft's OAuth 2.0 Device Authorization Grant flow to bypass MFA and hijack Microsoft 365 accounts; Cisco Talos exposed
EvilTokens is a turnkey, Telegram-distributed phishing-as-a-service (PhaaS) kit first documented by Sekoia's Threat Detection & Research team in March 2026 (pages circulating since mid-February 2026), sold for roughly $1,500 upfront plus a recurring monthly fee. Rather than harvesting passwords, the kit abuses Microsoft's legitimate OAuth 2.0 Device Authorization Grant flow: the attacker-controlled backend initiates a genuine device-code authentication request against Microsoft, then delivers the resulting code to the victim through a phishing lure. When the victim enters the code on the real microsoft.com/devicelogin page, they unknowingly authorize the attacker's session, and Microsoft issues a valid access and refresh token directly to the attacker's backend — silently defeating MFA without ever presenting a spoofed login form.
On July 1, 2026, Cisco Talos (researcher Michael Kelley) disclosed 'ARToken,' a React-based operator panel that functions as an EvilTokens affiliate/customer, sharing identical API contracts (an identical POST /api/device/start call) and infrastructure patterns. ARToken escalates initial device-code access into a Primary Refresh Token (PRT) by sending a non-standard clientMode:"broker" parameter that triggers Microsoft's Windows Authentication Broker (WAM) flow — a technique that keeps working even after the victim resets their password. The panel exposes more than 80 API endpoints spanning device-code initiation, PRT setup/refresh/renewal/cookie management, token export/import between operators, full Outlook mailbox read/send-as-victim access, automated malicious inbox-rule creation, cross-mailbox keyword monitoring, mass-BCC sending, and SharePoint/OneDrive browsing, upload, download, and permission management. AI/LLM-driven workflows score harvested mailboxes for financial exposure, draft BEC follow-up messages, and translate stolen email threads for multilingual operators — Talos assessed the platform as 'more mature than a simple device code phishing kit... a complete BEC operations environment.'
Evasion is handled by a seven-layer client-side anti-analysis system that fingerprints the browser to screen out headless browsers, automation frameworks, and crawlers; waits for genuine mouse movement or a touch event; imposes roughly a one-second activation delay; and only then unpacks an XOR-encrypted phishing payload in the browser, correlating the session via a LocalStorage key (artoken_jwt). This supersedes an earlier, simpler server-side X-Antibot-Token (64-character hex) header used by prior EvilTokens variants.
Campaigns use highly targeted, AI-generated, geo-aware vendor-impersonation lures — in one case-study Talos examined, an outstanding-invoice email spoofing a real Wisconsin plumbing-and-fire-protection contractor was sent to an accounts-payable contact at a U.S. life-sciences company; the visible link text displayed the vendor's genuine domain while the underlying href pointed to a look-alike SharePoint tenant hosted on an attacker-controlled Microsoft 365 workspace (resolving to legitimate sharepoint.com infrastructure to evade filters), and the message failed SPF, DKIM, and DMARC. Targeting concentrates on finance, HR, logistics, life-sciences, and public-sector accounts-payable staff.
A related but distinct April 2026 Microsoft-documented 'AI-enabled device code phishing' campaign shows the technique's broader commoditization: thousands of unique polling nodes hosted on Railway.com ran Node.js backend automation that generated device codes dynamically at the final redirect stage (defeating the standard 15-minute code expiry), used browser-in-the-browser fake verification prompts, hijacked the clipboard via navigator.clipboard.writeText to auto-paste the code, and polled a /state endpoint via checkStatus() every 3-5 seconds. Reconnaissance queried Microsoft's GetCredentialType endpoint 10-15 days before phishing delivery to validate target accounts at scale. Post-compromise, threat
Target sectors: life sciences, finance, human resources, logistics, accounts payable, public sector
Target regions: united states of america, canada, france, australia, india, switzerland, united arab emirates
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1598, T1589, T1591, T1583, T1584, T1587, T1608, T1585, T1566, T1566