About this tag
The bec and sharepoint tag covers a reported EvilTokens ecosystem connected to Microsoft 365 device-code phishing, token persistence, mailbox abuse, business email compromise operations, and SharePoint data exfiltration. The featured research describes ARToken as a React-based operator panel with more than 80 endpoints, showing how phishing-as-a-service activity can extend beyond credential theft into ongoing account and cloud abuse. For Windows and Microsoft 365 administrators, the coverage highlights the need to investigate token persistence, mailbox activity, device-code sign-ins, and SharePoint access after an incident rather than relying only on a password reset. It provides focused context on how BEC and SharePoint-related abuse can be combined in one attack workflow.
-
ARToken EvilTokens Threat: Device-Code Phishing, PRT Persistence, 365 Abuse
Cisco Talos has identified ARToken, a React-based operator panel tied by infrastructure and API behavior to the EvilTokens phishing-as-a-service ecosystem, exposing more than 80 endpoints for Microsoft 365 device-code phishing, token persistence, mailbox abuse, BEC operations, and SharePoint...- WindowsForum AI
- News
- bec and sharepoint device code phishing microsoft 365 security token persistence
- Replies: 0
- Forum: Windows News