Particle.news
Download on the App Store

ARToken Panel Identified as Full BEC‑as‑a‑Service Tied to EvilTokens

Researchers say the exposed management panel demonstrates that phishing platforms can bypass multi‑factor authentication and hold lasting access to Microsoft 365 accounts.

Overview

  • Cisco Talos found an exposed React management panel, labeled ARToken, that presented more than 80 endpoints for device‑code phishing, token escalation, mailbox control, inbox‑rule planting, and SharePoint/OneDrive theft.
  • The panel abused Microsoft’s device‑code (OAuth Device Authorization Grant) flow to capture tokens and offered a built‑in capability to escalate captured tokens into Primary Refresh Tokens that can survive password resets.
  • Researchers recovered phishing pages with a seven‑layer anti‑analysis system that waits for human interaction and uses look‑alike SharePoint tenants and vendor‑style invoice lures to trick accounts‑payable and other finance staff.
  • Talos linked ARToken to the EvilTokens affiliate ecosystem by overlapping technical fingerprints, but the specific operators remain unknown and the observed panel has gone dark and likely moved.
  • Defenders were given indicators by Talos and are advised to hunt for the published domains, watch for unexpected device‑code prompts, failed vendor authentication on invoice mail, and signs of token persistence because the BEC‑as‑a‑service model can scale targeted fraud and complicate remediation.