ARToken emerges: new phishing toolkit targets Microsoft 365, steals tokens without passwords
- Evelyn Carter

- Jul 6
- 3 min read
A newly identified phishing toolkit called ARToken is raising concerns across the cybersecurity community after researchers found it exploiting a legitimate Microsoft 365 authentication feature to hijack user sessions.
Rather than stealing passwords, ARToken tricks victims into authorizing a login request, allowing attackers to obtain valid access tokens that can be used to access Microsoft 365 resources.
What is ARToken and how does ARToken work?
According to a report from Cisco Talos, shared with Cyber Security News, ARToken was discovered during an investigation into phishing infrastructure. Researchers traced the toolkit's source code to an exposed management dashboard, revealing its complete feature set.
Because the authentication occurs on Microsoft's official website, the process appears trustworthy. Once the victim approves the request, the attacker receives a valid Microsoft 365 access token—without ever needing the user's password or multi-factor authentication (MFA) code.

Why is ARToken particularly dangerous?
ARToken goes far beyond stealing a single login session. The phishing panel includes more than 80 built-in functions that allow operators to refresh stolen tokens, access a victim's mailbox, and browse or download files stored in SharePoint and OneDrive.
Researchers also found that ARToken can elevate an initial access token into a Primary Refresh Token (PRT), allowing attackers to retain access even after the victim changes their password. This capability makes the attack significantly more persistent than traditional credential phishing campaigns.
Links to the EvilTokens phishing ecosystem
Cisco Talos noted that ARToken shares infrastructure, coding patterns, and backend commands with EvilTokens, a phishing-as-a-service (PhaaS) platform previously documented by Sekoia and later identified by Microsoft as a large-scale threat.
Before Microsoft publicly acknowledged the scale of Device Code Flow abuse, researchers had already tracked approximately 500 Cloudflare Workers domains and more than 2,000 phishing pages associated with the broader EvilTokens operation.
The campaign primarily targeted employees working in finance, human resources, and logistics, using AI-generated phishing messages tailored to individual victims.
Attack chain: From phishing email to account compromise
The attack typically begins with a phishing email impersonating a legitimate business contact instead of using a fake company identity.
In one case analyzed by researchers, attackers spoofed an accounts payable representative from a legitimate contractor and directed the recipient to what appeared to be a SharePoint invoice.
The phishing page then instructed the victim to enter a device code at microsoft page. Since this workflow is commonly used when signing into smart TVs or streaming devices, many users perceived the request as legitimate.
Built-in evasion and persistence capabilities
Before displaying the phishing workflow, ARToken performs a seven-layer screening process to filter out automated analysis systems and security scanners.
The toolkit checks browser fingerprints, monitors natural mouse movement, and intentionally delays page activation by nearly one second to verify that a real user—not a security bot—is interacting with the page.
Following compromise, operators can:
Read the victim's entire mailbox.
Send emails from the compromised account.
Create inbox rules to hide or automatically forward messages related to the intrusion.
Maintain long-term access using refreshed authentication tokens.
Defensive recommendations
Security teams should treat unexpected Device Code authentication requests as suspicious, particularly when they originate from invoice notifications or document-sharing emails.

Organizations should also encourage employees to verify unusual payment requests, document-sharing invitations, or authentication prompts through a trusted communication channel before approving any Microsoft login request.
What is the solution for protecting an organization's digital shield?
To ensure enterprise systems remain protected against the increasingly complex global cybersecurity landscape, organizations should consider working with trusted cybersecurity and IT service providers.

IPSIP Vietnam provides comprehensive cybersecurity and IT services designed to help businesses strengthen their security posture and respond effectively to emerging threats.
IPSIP Vietnam's management and monitoring systems have successfully passed rigorous assessments to achieve internationally recognized ISO 27001:2022 and SOC 2 Type II information security certifications. Through its core 24/7 services, including a Security Operations Center (SOC 24/7), a Network Operations Center (NOC 24/7), and dedicated IT support and helpdesk teams, IPSIP is committed to continuously monitoring, responding to, and blocking cyber intrusion attempts around the clock.
Reference











Comments