News · curated 3 Jul 2026

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Coverage timeline

1 Jul 2026talosintelligence.comprimarytheregister.com

Why it matters

It shows attackers operationalizing LLMs (Llama, GPT-4o-mini) inside a commercial phishing-as-a-service platform to scale MFA-bypassing token theft and BEC fraud.

Cisco Talos documents ARToken, a phishing-as-a-service affiliate panel sharing infrastructure with the EvilTokens platform, that abuses Microsoft's OAuth device authorization grant to steal tokens and bypass MFA. The AI element is an AI-augmented BEC pipeline chaining Groq-hosted Llama models for financial exposure scoring and GPT-4o-mini for email translation, plus AI-powered personalized lures, to automate fraud against compromised Microsoft 365 mailboxes.