Cisco Talos uncovers phishing platform that bypasses MFA in Microsoft 365
Cisco Talos has analysed ARToken, a phishing-as-a-service panel linked to the EvilTokens ecosystem targeting Microsoft 365. The platform abuses Microsoft's device code authentication flow to capture tokens and thereby bypass multi-factor authentication. Talos found shared infrastructure and operational patterns between ARToken and EvilTokens, with capabilities for token persistence, mailbox access, SharePoint and OneDrive access, inbox rule creation and business email compromise.
What this means for your organisation
MFA on its own does not stop this. Once the attacker holds a valid token, the account behaves like a normal authenticated user, and the access covers both mail and document storage. The combination of inbox rules and invoice fraud is the classic path from account takeover to direct financial loss, and the barrier is low for Norwegian organisations because Microsoft 365 is the default platform.
Berigo recommends
- Disable device code authentication in Entra ID where it is not actively used, and constrain it with conditional access elsewhere.
- Require compliant or registered devices for access to mail and SharePoint.
- Monitor the creation of inbox rules and forwarding to external addresses, and alert on it automatically.
- Put a procedure in place for immediate token revocation on suspected account takeover, not just a password reset.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch