As cited
Copy frozen at (site build).
threat intel
Catan and Mouse
Cisco Talos published research on ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and patterns with the previously documented EvilTokens platform. The panel provides 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration through a React-based dashboard, indicating a mature BEC operations environment rather than a basic phishing kit.
Why it matters: Organizations using Microsoft 365 and SharePoint are at risk from operators leveraging this advanced BEC platform; security teams should use the provided indicators of compromise to block activity and hunt for signs of compromise in their environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Catan and Mouse
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Catan and Mouse
Cisco Talos documented ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and operational patterns with the EvilTokens platform. The panel provides over 80 application programming interface (API) endpoints enabling device code phishing, token persistence, email compromise, and data exfiltration through a dashboard interface, positioning it as a mature business email compromise (BEC) operations platform rather than a simple phishing kit.
Why it matters: Defenders managing email security and identity systems need to apply the indicators of compromise from Talos research to block malicious activity and conduct internal hunts for signs of ARToken exploitation in their environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Catan and Mouse
Cisco Talos documented ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and operational patterns with the EvilTokens platform. The panel provides over 80 application programming interface (API) endpoints enabling device code phishing, token persistence, email compromise, and data exfiltration through a dashboard interface, positioning it as a mature business email compromise (BEC) operations platform rather than a simple phishing kit.
Why it matters: Defenders managing email security and identity systems need to apply the indicators of compromise from Talos research to block malicious activity and conduct internal hunts for signs of ARToken exploitation in their environments.
- Source published
- First seen by Cybersecurity Tracker