Skip to content
Security Threats 4 July 2026

ARToken PhaaS puts a professional phishing toolkit within reach of any attacker

Diixtra | BleepingComputer

Security researchers have pulled back the curtain on ARToken, a phishing-as-a-service platform linked to the EvilTokens ecosystem. The toolkit is purpose-built to compromise Microsoft 365 accounts, and its sophistication is notable: rather than targeting credentials directly, it intercepts session tokens — the short-lived authentication cookies that sit between the user and the service. Once an attacker has a valid session token, multi-factor authentication offers no further protection, because the authentication step has already been completed.

Why Token Theft Changes the Threat Model

Traditional phishing attacked passwords. Modern adversary-in-the-middle (AiTM) attacks go further: they proxy the victim’s real login through an attacker-controlled relay, harvesting the authenticated session token in real time. The victim sees what looks like a normal login flow. Microsoft’s MFA prompt fires and is satisfied. The attacker captures the resulting session cookie and replays it from their own device.

This technique is not new, but packaging it into a productised, affiliate-distributed PhaaS platform dramatically lowers the barrier to entry. What previously required operational skill and custom tooling is now available as a service. The ARToken disclosure suggests this tooling is actively being developed, improved, and distributed through criminal affiliate networks.

Practical Steps for Microsoft 365 Administrators

Standard MFA remains worth having — it eliminates the most common credential-stuffing attacks — but organisations must go further. Conditional Access policies should enforce device compliance requirements, restricting access to managed or compliant devices where possible. Sign-in risk policies, available through Microsoft Entra ID (formerly Azure AD) Identity Protection, can automatically block or challenge sessions that appear anomalous.

Token lifetime reduction is another lever: shorter-lived sessions reduce the window of usefulness for a stolen cookie. Continuous Access Evaluation, available in Microsoft’s higher-tier licensing tiers, revokes tokens in near-real time when risk signals change.

For ops leaders: if your Microsoft 365 environment is protected only by SMS-based MFA and has no Conditional Access policies in place, this disclosure warrants an urgent review. The tooling to exploit that configuration is now commoditised.

Source: BleepingComputer

Want to discuss this topic?

Book a free discovery call and we'll explore how this applies to your business.