Executive Summary
A highly sophisticated Phishing-as-a-Service (PhaaS) ecosystem, identified as EvilTokens and its affiliate panel ARToken, is actively targeting US and European organizations across the technology, manufacturing, and financial sectors. This platform leverages Microsoft's OAuth 2.0 Device Authorization Grant to capture user tokens and Primary Refresh Tokens (PRTs), effectively bypassing multi-factor authentication (MFA) and maintaining persistent access even after password resets. Operators utilize an automated Business Email Compromise (BEC) pipeline featuring AI-augmented email translation and financial exposure scoring to monetize compromised accounts.
Technically, the threat is notable for its use of 'ghost' code—landing pages encrypted with AES-GCM or XOR that only decrypt within the victim's browser, successfully evading static URL analysis and traditional security gateways. The ARToken affiliate panel reveals a comprehensive post-compromise toolkit, including ARTSender for automated inbox rule manipulation and mass-mailing, and ARTBrowser, a dedicated tool for navigating victim sessions. The high success rate and operational maturity of these platforms represent a significant risk to corporate data and internal communications.
Key Details
Threat Name
EvilTokens
Affects
Cisco Catalyst SD-WAN Controller, Cisco Catalyst SD-WAN Manager, SD-WAN vSmart, SD-WAN vManage, Cisco Firepower devices, Firepower eXtensible Operating System (FXOS)
Adversary
Kali365 Other Adversaries and Aliases: EvilTokens; ARToken; UAT-4356
MITRE Techniques
Malware/Tools
EvilTokens, JS.MonoGlyphRAT, Remcos RAT, Kamasers, MicroStealer, ARToken, ARTSender, ARTBrowser
