July 3, 2026
- Cisco Talos dissected an EvilTokens affiliate panel branded ARToken, a phishing-as-a-service platform targeting Microsoft 365 with 80+ API endpoints for device-code phishing, Primary Refresh Token (PRT) persistence, mailbox access, BEC, and SharePoint exfiltration — sharing infrastructure with the EvilTokens kit documented by Sekoia and Microsoft. Related reporting covers ConsentFix/ClickFix OAuth token theft that hijacks accounts "in three seconds." Talos, BleepingComputer. · Cloud & Identity
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire