Skip to content
Security Threats 3 July 2026

Phishing-as-a-service now targets Microsoft 365 with industrial-scale toolkits

Diixtra | BleepingComputer

Security researchers have uncovered ARToken, a phishing-as-a-service (PhaaS) platform operating as an affiliate of the EvilTokens toolkit. What makes this significant is the specificity of its targeting: ARToken is built from the ground up to compromise Microsoft 365 accounts, using adversary-in-the-middle (AiTM) techniques that can bypass multi-factor authentication entirely.

A Toolkit Designed for Scale

The industrialisation of phishing is not new, but dedicated M365 platforms represent a qualitative shift in attacker capability. Subscribers to a PhaaS like ARToken no longer need to build their own phishing infrastructure. They choose a target domain, customise a lure, and the platform handles credential harvesting, session interception, and exfiltration. Technical skill is no longer a meaningful barrier to running a sophisticated credential theft campaign.

The EvilTokens ecosystem behind ARToken also provides defenders with a rare window into the breadth of tooling available to attackers. The platform includes features for evading automated detection, rendering convincing M365 login replicas, and managing stolen sessions at scale.

Why MFA Is No Longer a Sufficient Control on Its Own

The AiTM technique at the core of ARToken is important to understand. Traditional phishing captures a password. AiTM phishing intercepts the authentication session itself, capturing the session token after the victim has successfully completed MFA. The attacker replays that token and gains full account access without ever needing the password or the one-time code.

This means organisations that have ticked MFA off their security checklist and considered the job done are carrying a significant false sense of security. MFA is still necessary — but it is no longer sufficient against modern phishing toolkits.

What M365 Administrators Should Do Now

Three controls are worth prioritising. First, implement Conditional Access policies that require compliant or hybrid-joined devices — this limits session token replay to managed devices only. Second, review sign-in audit logs for anomalous authentication patterns, particularly sign-ins from unexpected geographic regions or unfamiliar device types. Third, evaluate phishing-resistant authentication options — passkeys and hardware security keys — for privileged accounts where the risk is highest.

The ARToken exposure is a useful reminder that the threat model for M365 has evolved far beyond password compromise. Controls need to keep pace.

Read the full story on BleepingComputer

Want to discuss this topic?

Book a free discovery call and we'll explore how this applies to your business.