INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

EvilTokens Affiliate Panel Targets Microsoft 365 with Phishing Toolkit

| 2026-07-01 10:00 CRITICAL HIGH PHISHING & SOCIAL ENGINEERING
Executive Summary
AI-generated
A new phishing-as-a-service (PhaaS) platform dubbed "ARToken" appears to operate as an affiliate of the EvilTokens phishing platform, exposing over 80 API endpoints and revealing extensive capabilities designed to compromise Microsoft 365. The attack works by using a React-based management panel called "ARToken Panel", allowing attackers to steal authentication tokens, establish persistent access using Primary Refresh Tokens (PRTs), and access various Microsoft services such as Outlook mailboxes and OneDrive files. As of the latest report from Cisco Talos researchers on July 3rd, 2026, multiple technical similarities suggest ARToken is tied to EvilTokens, with identical API calls for device code authentication flow and primary refresh token endpoints previously documented in Sekoia's research. The current status indicates that this phishing toolkit has been exposed, providing a glimpse into the extensive capabilities of the EvilTokens platform, which was first documented by Sekoia in March 2026.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
cl•••••.dev
sp•••••.com
da•••••.com
pu•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
‎March 2026
Threat actors using EvilTokens' phishing-as-a-service exploited Microsoft's OAuth 2.0 Device Authorization Grant to bypass multi-factor authentication and capture victim tokens.
tactic Phishing
organisation MFA
general_metric 2.0 OAuth
‎April 2026
EvilTokens' affiliate panel targeted Microsoft 365 using vendor-impersonation invoice fraud, with the campaign's scale confirmed by Microsoft in April 2026.
organisation Cloudflare Workers
infrastructure 500 Workers domains
organisation Groq
financial $500 $ lifetime
‎April 20, 2026
Threat actors used ARToken's API surface to target Microsoft 365, utilizing a phishing kit with identical lifecycle and deployment model as EvilTokens.
organisation SPA
organisation MB
infrastructure 1.7 compiled JavaScript bundle
organisation POST
organisation UUID
organisation Cloudflare
organisation Listing deployed Workers Deploying
organisation Workers
organisation UI
data_breach 16 byte
infrastructure Microsoft 365
infrastructure Windows
victims 365 victim sessions
organisation ARToken Panel
organisation Authentication Broker
organisation PRT
organisation Adobe
organisation OneDrive
organisation Affiliates
organisation AES
organisation Token
‎2026/07/01
Threat actors using the EvilTokens affiliate panel exploited Microsoft 365's OAuth 2.0 Device Authorization Grant authentication workflow to breach accounts via device code phishing attacks.
organisation BEC
organisation SharePoint
organisation XOR
victims 1 User Agent
organisation JWT
organisation BCC
organisation Inbox
organisation Keyword
organisation Operators
organisation Shared
organisation Initial Access
organisation Credential Access
organisation Collection
organisation Resource Development
organisation T1583.006 Stealth
organisation Stealth
infrastructure Microsoft 365
infrastructure 80 API endpoints
financial $500 $ lifetime
financial $1,500 $ setup fee
victims 365 victim sessions
organisation EvilTokens
‎early 2026
Threat actors using the ARToken affiliate panel exploited phishing-as-a-service capabilities to target Microsoft 365.
tactic Phishing
organisation ARToken
organisation API
organisation Sekoia
organisation Microsoft
Tactical Metrics
Metrics
infrastructure
500
Workers Domains
Metrics
infrastructure
2
Compiled Javascript Bundle
Metrics
victims
1
User Agent
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
365
Victim Sessions
Metrics
data_breach
16
Byte
Metrics
financial
500
$ Lifetime
Metrics
infrastructure
80
Api Endpoints
Metrics
financial
1,500
$ Setup Fee
Intelligence Sources
BleepingComputer 2026-07-03
Talos Intelligence 2026-07-01