EvilTokens and ARToken PhaaS Analysis
Score: 8/10

EvilTokens and ARToken PhaaS Analysis

The EvilTokens and ARToken Phishing-as-a-Service (PhaaS) platforms use Microsoft Device Code flows and browser-side decryption to bypass MFA and achieve persistent Microsoft 365 account takeovers.

Executive Summary

A highly sophisticated Phishing-as-a-Service (PhaaS) ecosystem, identified as EvilTokens and its affiliate panel ARToken, is actively targeting US and European organizations across the technology, manufacturing, and financial sectors. This platform leverages Microsoft's OAuth 2.0 Device Authorization Grant to capture user tokens and Primary Refresh Tokens (PRTs), effectively bypassing multi-factor authentication (MFA) and maintaining persistent access even after password resets. Operators utilize an automated Business Email Compromise (BEC) pipeline featuring AI-augmented email translation and financial exposure scoring to monetize compromised accounts.

Technically, the threat is notable for its use of 'ghost' code—landing pages encrypted with AES-GCM or XOR that only decrypt within the victim's browser, successfully evading static URL analysis and traditional security gateways. The ARToken affiliate panel reveals a comprehensive post-compromise toolkit, including ARTSender for automated inbox rule manipulation and mass-mailing, and ARTBrowser, a dedicated tool for navigating victim sessions. The high success rate and operational maturity of these platforms represent a significant risk to corporate data and internal communications.

Key Details

Threat Name

EvilTokens

Affects

Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, SD-WAN vSmart, SD-WAN vManage, Cisco Firepower devices, Firepower eXtensible Operating System (FXOS)

Adversary

Kali365 Other Adversaries and Aliases: EvilTokens; ARToken; UAT-4356

Malware/Tools

EvilTokens, JS.MonoGlyphRAT, Remcos RAT, Kamasers, MicroStealer, ARToken, ARTSender, ARTBrowser

Report Score

8out of 10
Quality Score
Good
IOC Quality7
TTP Details9
Detection Guidance6
Enterprise Relevance10
Clarity & Structure8
Technical Depth9

Sources