Warning: ARToken Phishing Kit Automates BEC Attacks

KnowBe4 Team | Jul 22, 2026

Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called “ARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.

“The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration — all accessible to operators through a React-based dashboard,” Talos says.

In an attack observed by Talos, the phishing lures were tailored to the targeted organization, impersonating a legitimate vendor used by the company.

“The messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life-sciences company — abusing a real vendor relationship rather than inventing a sender,” the researchers write. “The lure theme is an outstanding-invoice query (‘the following invoices appear to still be outstanding… advise when this will be processed’), the kind of message accounts-payable staff are conditioned to act on.”

The kit includes a full-fledged business email compromise tool with the following capabilities:

  • “Full Outlook inbox read access per compromised account
  • Email sending as the victim with BCC batch support and configurable inter-send delays
  • Inbox rule creation for forwarding and auto-deletion (evidence suppression)
  • Keyword-based monitoring across all compromised accounts simultaneously
  • Email attachment access and download”

The researchers note that the phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads, a more sophisticated evasion approach than the server-side X-Antibot-Token mechanism documented in prior EvilTokens research.”

Cisco Talos has the story: ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

See KnowBe4 Defend™ in Action

Learn how Defend™ strategically enhances Microsoft 365's native security to catch the threats Secure Email Gateways (SEGs) miss.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.