ARToken Device Code Phishing for Microsoft 365
Score: 9/10

ARToken Device Code Phishing for Microsoft 365

ARToken is a Phishing-as-a-Service platform that abuses Microsoft's OAuth 2.0 device code flow to bypass MFA and achieve full Entra tenant takeover.

Executive Summary

ARToken is a sophisticated Microsoft 365 account takeover Phishing-as-a-Service (PhaaS) platform first observed in July 2026. Unlike traditional phishing that mimics login pages, ARToken abuses the legitimate Microsoft OAuth 2.0 device-authorization grant flow. It tricks victims into entering a real device code on Microsoft's genuine login portal, allowing attackers to capture authenticated access and refresh tokens while bypassing MFA controls.

The platform provides a comprehensive post-compromise console that enables affiliates to maintain persistence via device registration and Primary Refresh Tokens (PRTs), proxy Microsoft Graph requests, and escalate privileges within Entra tenants. By centralizing lure creation, token management, and mailbox monitoring for financial keywords, ARToken lowers the barrier for cybercriminals to conduct highly effective business email compromise (BEC) and tenant-wide lateral movement.

This threat is particularly critical for finance and accounts payable departments, as many lures are themed around invoices and shared documents. Because the authentication occurs on legitimate Microsoft infrastructure, traditional domain-based blocklists and standard MFA are insufficient defenses against this campaign.

Key Details

Threat Name

ARToken Phishing Platform

Affects

—

Adversary

ARToken

Malware/Tools

ARToken, ARTSender

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources