Phishing Attack: How ARToken Targets Microsoft 365 Accounts

www.news4hackers.com-phishing-attack-how-artoken-targets-microsoft-365-accounts-phishing-attack-how-artoken-targets-microsoft-365-accounts

Accounts-payable teams at U.S. organizations have been receiving invoice emails that mimic communications from established vendors.

The ARToken Phishing Panel Targets Microsoft 365 Accounts

Accounts-payable teams at U.S. organizations have been receiving invoice emails that mimic communications from established vendors. One such message reached a life-sciences company in April 2026, addressed to an employee responsible for payments. The email was crafted to appear as if it originated from a Wisconsin contractor’s billing contact, referencing outstanding invoices typical of routine accounts-payable inquiries. This deception is part of a phishing campaign linked to EvilTokens, a subscription-based service that leveraged hundreds of Cloudflare Workers domains earlier in 2026.

The Attack on a U.S. Life-Sciences Company

Cisco Talos identified two nearly identical messages sent minutes apart on April 20, 2026, both impersonating an accounts-payable contact at a legitimate Wisconsin vendor. These emails were delivered to a U.S. life-sciences company’s payments team. The attackers exploited existing vendor relationships to bypass suspicion, using the genuine vendor domain in the “From” field while redirecting replies through a spoofed “Reply-To” address. All email authentication protocols—SPF, DKIM, and DMARC—failed, indicating deliberate spoofing.

EvilTokens and the Subscription Model

The email contained a link masquerading as the vendor’s SharePoint tenant, which redirected to a cloned tenant hosted in an attacker-controlled Microsoft 365 workspace. This cloned environment utilized a legitimate sharepoint.com domain, leveraging Microsoft’s reputation to evade detection. The messages included randomized text and an inline signature image, features consistent with minor variations designed to bypass automated content filters. EvilTokens, the platform behind this attack, exploits Microsoft’s OAuth 2.0 Device Authorization Grant, a protocol intended for devices without keyboards.

The Cloned SharePoint Tenant and Authentication Bypass

This allows the service to capture authentication tokens during the sign-in process, bypassing multi-factor authentication. Sekoia documented the platform in March 2026, and Microsoft later confirmed its scale, noting higher success rates compared to previous device-code phishing attacks and AI-generated lures tailored to individual targets. By March 2026, Sekoia had identified approximately 500 Cloudflare Workers domains associated with the platform, with affiliates targeting finance, HR, and logistics personnel globally.

The ARToken Panel and Its Capabilities

The platform operates on a subscription model, requiring an initial payment of $1,500 plus a monthly fee. Its secondary stage employs an AI-assisted business compromise pipeline, transforming hijacked mailboxes into customized fraud scenarios. During an incident response, Talos traced the infrastructure to an exposed management panel named ARToken Panel, a React-based web application. This panel’s client-side code was fully delivered to the browser, revealing internal routes and endpoints accessible through a single dashboard.

The Seven-Layer Defense System

The interface included over 80 endpoints, enabling device-code phishing, token persistence, mailbox access, business compromise, and SharePoint theft. Technical overlaps between ARToken and EvilTokens include identical sign-in requests, shared broker modes for retrieving Primary Refresh Tokens via Microsoft’s Authentication Broker, and lures deployed on Cloudflare Workers under similar subdomain patterns. The ARToken panel also incorporates the Primary Refresh Token lifecycle, a key advancement identified by Sekoia.

Operator Insights and Infrastructure

While no definitive operator has been identified, the platform appears to be an affiliate-driven variant rather than a centralized operation, according to Michael Kelley, a Cisco Talos researcher. The phishing page associated with ARToken employs a seven-layer defense system to evade automated scanners. Early checks block headless browsers and automation tools by analyzing browser characteristics, while later stages wait for user interaction—such as mouse movements or screen touches—before deploying the payload.

Detection and Mitigation Strategies

The payload is scrambled and unpacked in the browser, preventing URL-based scanners from detecting it. One configuration disables token persistence after a password change, indicating awareness of how password resets invalidate stolen credentials. Operators using the panel gain access to a dashboard where captured tokens enable a range of actions, including refreshing tokens into Primary Refresh Tokens that survive password resets, reading and sending emails, creating inbox rules to conceal evidence, and accessing SharePoint and OneDrive for data exfiltration.

Conclusion

The attack highlights the evolving sophistication of phishing operations targeting enterprise environments. By combining social engineering, advanced authentication bypass techniques, and AI-driven customization, threat actors continue to refine methods for compromising critical business systems. Organizations are urged to monitor for anomalies in email authentication, scrutinize unexpected device-code prompts, and implement robust endpoint detection and response strategies to mitigate such threats.

“While no coordinated takedown occurred, the infrastructure likely relocated,” said Michael Kelley, a Cisco Talos researcher.



About Author

en_USEnglish