top of page

ARToken emerges: new phishing toolkit targets Microsoft 365, steals tokens without passwords

A newly identified phishing toolkit called ARToken is raising concerns across the cybersecurity community after researchers found it exploiting a legitimate Microsoft 365 authentication feature to hijack user sessions.

Rather than stealing passwords, ARToken tricks victims into authorizing a login request, allowing attackers to obtain valid access tokens that can be used to access Microsoft 365 resources.

What is ARToken and how does ARToken work?

According to a report from Cisco Talos, shared with Cyber Security News, ARToken was discovered during an investigation into phishing infrastructure. Researchers traced the toolkit's source code to an exposed management dashboard, revealing its complete feature set.

Because the authentication occurs on Microsoft's official website, the process appears trustworthy. Once the victim approves the request, the attacker receives a valid Microsoft 365 access token—without ever needing the user's password or multi-factor authentication (MFA) code.

What is ARToken and how does ARToken work?
sWhat is ARToken and how does ARToken work?

Why is ARToken particularly dangerous?

ARToken goes far beyond stealing a single login session. The phishing panel includes more than 80 built-in functions that allow operators to refresh stolen tokens, access a victim's mailbox, and browse or download files stored in SharePoint and OneDrive.

Researchers also found that ARToken can elevate an initial access token into a Primary Refresh Token (PRT), allowing attackers to retain access even after the victim changes their password. This capability makes the attack significantly more persistent than traditional credential phishing campaigns.

Links to the EvilTokens phishing ecosystem

Cisco Talos noted that ARToken shares infrastructure, coding patterns, and backend commands with EvilTokens, a phishing-as-a-service (PhaaS) platform previously documented by Sekoia and later identified by Microsoft as a large-scale threat.

Before Microsoft publicly acknowledged the scale of Device Code Flow abuse, researchers had already tracked approximately 500 Cloudflare Workers domains and more than 2,000 phishing pages associated with the broader EvilTokens operation.

The campaign primarily targeted employees working in finance, human resources, and logistics, using AI-generated phishing messages tailored to individual victims.

Attack chain: From phishing email to account compromise

The attack typically begins with a phishing email impersonating a legitimate business contact instead of using a fake company identity.

In one case analyzed by researchers, attackers spoofed an accounts payable representative from a legitimate contractor and directed the recipient to what appeared to be a SharePoint invoice.

The phishing page then instructed the victim to enter a device code at microsoft page. Since this workflow is commonly used when signing into smart TVs or streaming devices, many users perceived the request as legitimate.

Built-in evasion and persistence capabilities

Before displaying the phishing workflow, ARToken performs a seven-layer screening process to filter out automated analysis systems and security scanners.

The toolkit checks browser fingerprints, monitors natural mouse movement, and intentionally delays page activation by nearly one second to verify that a real user—not a security bot—is interacting with the page.

Following compromise, operators can:

  • Read the victim's entire mailbox.

  • Send emails from the compromised account.

  • Create inbox rules to hide or automatically forward messages related to the intrusion.

  • Maintain long-term access using refreshed authentication tokens.

Defensive recommendations

Security teams should treat unexpected Device Code authentication requests as suspicious, particularly when they originate from invoice notifications or document-sharing emails.

Defensive recommendations
Defensive recommendations

Organizations should also encourage employees to verify unusual payment requests, document-sharing invitations, or authentication prompts through a trusted communication channel before approving any Microsoft login request.

What is the solution for protecting an organization's digital shield?

To ensure enterprise systems remain protected against the increasingly complex global cybersecurity landscape, organizations should consider working with trusted cybersecurity and IT service providers.

IPSIP Vietnam cybersecurity solutions
IPSIP Vietnam cybersecurity solutions

IPSIP Vietnam provides comprehensive cybersecurity and IT services designed to help businesses strengthen their security posture and respond effectively to emerging threats.

IPSIP Vietnam's management and monitoring systems have successfully passed rigorous assessments to achieve internationally recognized ISO 27001:2022 and SOC 2 Type II information security certifications. Through its core 24/7 services, including a Security Operations Center (SOC 24/7), a Network Operations Center (NOC 24/7), and dedicated IT support and helpdesk teams, IPSIP is committed to continuously monitoring, responding to, and blocking cyber intrusion attempts around the clock.

Reference


Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page