CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Catan and Mouse

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 348

As cited

Copy frozen at (site build).

threat intel

Catan and Mouse

Cisco Talos published research on ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and patterns with the previously documented EvilTokens platform. The panel provides 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration through a React-based dashboard, indicating a mature BEC operations environment rather than a basic phishing kit.

Why it matters: Organizations using Microsoft 365 and SharePoint are at risk from operators leveraging this advanced BEC platform; security teams should use the provided indicators of compromise to block activity and hunt for signs of compromise in their environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Catan and Mouse

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Catan and Mouse

Cisco Talos documented ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and operational patterns with the EvilTokens platform. The panel provides over 80 application programming interface (API) endpoints enabling device code phishing, token persistence, email compromise, and data exfiltration through a dashboard interface, positioning it as a mature business email compromise (BEC) operations platform rather than a simple phishing kit.

Why it matters: Defenders managing email security and identity systems need to apply the indicators of compromise from Talos research to block malicious activity and conduct internal hunts for signs of ARToken exploitation in their environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Catan and Mouse

Cisco Talos documented ARToken, a phishing-as-a-service (PhaaS) operator panel that shares infrastructure and operational patterns with the EvilTokens platform. The panel provides over 80 application programming interface (API) endpoints enabling device code phishing, token persistence, email compromise, and data exfiltration through a dashboard interface, positioning it as a mature business email compromise (BEC) operations platform rather than a simple phishing kit.

Why it matters: Defenders managing email security and identity systems need to apply the indicators of compromise from Talos research to block malicious activity and conduct internal hunts for signs of ARToken exploitation in their environments.

VendorsMicrosoftCisco
Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary