New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts
Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft’s device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The kit shares code and infrastructure with the EvilTokens phishing-as-a-service operation and gives operators an 80-plus function dashboard for post-compromise abuse.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.