A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing,…
The post EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft appeared first on IT Security News.