INTEL_REPORT
Cisco Talos Blog · published 7/1/2026, 10:00:38 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API cont…
https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365
sha256:739a8e4a8240a0facca4fbbfbfbfaeb953680b0ef5abff7b8ae2d06a2e2e6270
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| spx.pamconj.com |
| Open → |
| domain | clear90489058903-document.workers.dev | Open → |
| domain | docviewer.workers.dev | Open → |
| domain | onedrive.workers.dev | Open → |
| domain | adobe2.workers.dev | Open → |
| domain | s-account.workers.dev | Open → |
| domain | navigator.webdriver | Open → |
| domain | navigator.vendor | Open → |