News · curated 3 Jul 2026
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
First reported · updated · 2 reports talosintelligence.com
Coverage timeline
Why it matters
It shows attackers operationalizing LLMs (Llama, GPT-4o-mini) inside a commercial phishing-as-a-service platform to scale MFA-bypassing token theft and BEC fraud.
Cisco Talos documents ARToken, a phishing-as-a-service affiliate panel sharing infrastructure with the EvilTokens platform, that abuses Microsoft's OAuth device authorization grant to steal tokens and bypass MFA. The AI element is an AI-augmented BEC pipeline chaining Groq-hosted Llama models for financial exposure scoring and GPT-4o-mini for email translation, plus AI-powered personalized lures, to automate fraud against compromised Microsoft 365 mailboxes.