Executive Summary
ARToken is a sophisticated Microsoft 365 account takeover Phishing-as-a-Service (PhaaS) platform first observed in July 2026. Unlike traditional phishing that mimics login pages, ARToken abuses the legitimate Microsoft OAuth 2.0 device-authorization grant flow. It tricks victims into entering a real device code on Microsoft's genuine login portal, allowing attackers to capture authenticated access and refresh tokens while bypassing MFA controls.
The platform provides a comprehensive post-compromise console that enables affiliates to maintain persistence via device registration and Primary Refresh Tokens (PRTs), proxy Microsoft Graph requests, and escalate privileges within Entra tenants. By centralizing lure creation, token management, and mailbox monitoring for financial keywords, ARToken lowers the barrier for cybercriminals to conduct highly effective business email compromise (BEC) and tenant-wide lateral movement.
This threat is particularly critical for finance and accounts payable departments, as many lures are themed around invoices and shared documents. Because the authentication occurs on legitimate Microsoft infrastructure, traditional domain-based blocklists and standard MFA are insufficient defenses against this campaign.
