Your users authenticate through Microsoft’s own login page. Your MFA fires. Access is granted. And the attacker just stole their session anyway. That is not a vulnerability — it is a feature of the OAuth device code flow that threat actors are weaponizing at scale.

Cisco Talos has uncovered ARToken, a phishing-as-a-service platform tied to the EvilTokens ecosystem, designed to compromise Microsoft 365 accounts by harvesting authentication tokens rather than passwords. The platform exposes a React-based management panel with over 80 API endpoints — a clear sign that token theft has matured from niche technique to industrial-scale criminal enterprise.

What makes ARToken dangerous is not the phishing lure itself — it is what comes after. Once a victim completes Microsoft’s legitimate device code authentication flow, attackers capture Primary Refresh Tokens (PRTs). These tokens grant persistent access to Outlook, SharePoint, OneDrive, and the ability to send email as the compromised user — all without ever needing the password again. Sekoia’s earlier research found that EvilTokens affiliates paid US$1,500 setup fees and US$500 monthly subscriptions for access to this capability. The ROI for attackers is clear, and the bar to entry keeps dropping.

What security leaders should do:

  • Disable device code authentication flows for end users. Microsoft allows tenant-level controls — use Conditional Access policies to block device code flows except where explicitly needed for headless applications.
  • Monitor for anomalous Primary Refresh Token activity. Look for token requests from unfamiliar IP ranges, unusual geographies, or device profiles that don’t match your user population. SIEM rules that flag device code auth completions from non-corporate networks are a solid starting point.
  • Audit inbox rules daily. ARToken’s ability to create rules that auto-forward or hide messages means the standard “check for forwarding rules” is no longer enough — attackers hide their presence with rules that delete or archive compromise notifications.

These attacks are succeeding because they abuse Microsoft’s own trust infrastructure. Your security stack catches the phishing email only at the first mile — but the attacker has already moved past MFA, past Conditional Access, and into the session layer. That is the gap we need to close.

#CyberSecurity #EmailSecurity #IdentitySecurity #Microsoft365 #Phishing

Source: BleepingComputer


Leave a Reply

Your email address will not be published. Required fields are marked *