Researchers at Cisco Talos are tracking a sophisticated phishing-as-a-service operator panel called “ARToken” that’s built on the EvilTokens phishing platform. ARToken focuses on targeted social engineering attacks, allowing operators to customize phishing attempts for each victim.
“The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration — all accessible to operators through a React-based dashboard,” Talos says.
In an attack observed by Talos, the phishing lures were tailored to the targeted organization, impersonating a legitimate vendor used by the company.
“The messages spoof an accounts-payable contact at a legitimate Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life-sciences company — abusing a real vendor relationship rather than inventing a sender,” the researchers write. “The lure theme is an outstanding-invoice query (‘the following invoices appear to still be outstanding… advise when this will be processed’), the kind of message accounts-payable staff are conditioned to act on.”
The kit includes a full-fledged business email compromise tool with the following capabilities:
- “Full Outlook inbox read access per compromised account
- Email sending as the victim with BCC batch support and configurable inter-send delays
- Inbox rule creation for forwarding and auto-deletion (evidence suppression)
- Keyword-based monitoring across all compromised accounts simultaneously
- Email attachment access and download”
The researchers note that the phishing kit also “deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads, a more sophisticated evasion approach than the server-side X-Antibot-Token mechanism documented in prior EvilTokens research.”
Cisco Talos has the story: ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
