VNVũ Nhật Lâminblog.fiscybersec.com·Jul 28 · 9 min readEvilTokens and "Ghost Phishing": The Microsoft 365 Attack That Only Materializes Inside the BrowserEvilTokens, a phishing-as-a-service (PhaaS) kit that surfaced in mid-February 2026, chains two techniques that together defeat both static URL scanning and multi-factor authentication. The phishing HT00
VNVũ Nhật Lâminblog.fiscybersec.com·Jul 19 · 10 min readARToken & EvilTokens: The AI-Augmented Device Code Phishing PhaaS Hijacking Microsoft 365 and Automating BEC FraudExecutive Summary ARToken is a Phishing-as-a-Service (PhaaS) operator panel published by Cisco Talos on July 1, 2026, which Talos assesses to be an affiliate panel of the EvilTokens platform — the Pha00