ARToken
tool · tool:talos-artoken-eviltokens-bec-panel single-source
EvilTokens-lineage BEC-as-a-service panel targeting Microsoft 365 (Cisco Talos).
Coverage
2
first 2026-07-02 → last 2026-07-29
Latest activity
2026-07-29
Cisco Talos IR's quarterly report puts three named intrusion chains on record, led by Sinobi running its…
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, healthcare, manufacturing
Sources cited
3
2 hosts
2026-07-022 appearances2026-07-29
Action items (2)
Do-now tasks recorded on the entries about ARToken, newest first. Check the date before acting on an older one.
- Cross-check your asset inventory for MeshCentral MeshAgent and Zoho Assist Unattended Agent instances that your own management platform did not provision, treating any such agent running as a SYSTEM auto-start service as an incident rather than a hygiene finding; both were the primary command-and-control mechanism in the ransomware engagements Talos describes.2026-07-29Cisco Talos IR's quarterly report puts three named…
- Raise domain-controller security-log retention and forward it off-device: Talos found DC logs retained for only a few hours, and states the resulting gaps prevented determining the initial access vector or exfiltration scope in real engagements; 90 days of centralised retention is the figure it names.2026-07-29Cisco Talos IR's quarterly report puts three named…
Defender insights
What each entry about ARToken tells a defender to do, newest first.
Triage
Detection
Story timeline
- 2026-07-29Talos IR Trends Q2 2026: ransomware operators ran their command-and-control through legitimate RMM agents, authentication abuse hit two-thirds of engagements, and missing logs stopped root-cause determination outright
- 2026-07-02Cisco Talos: "ARToken" exposes a full BEC-as-a-service toolkit on top of Microsoft 365 device-code phishing
Hunting pivots
Affected products
ATT&CK techniques (25 across 12 tactics)
25 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissancePhishing for Information
- Initial AccessValid Accounts · Exploit Public-Facing Application · Phishing: Spearphishing Attachment · Phishing: Spearphishing Link
- PersistenceValid Accounts · Account Manipulation: Additional Cloud Credentials · Account Manipulation: Device Registration · Create or Modify System Process: Windows Service
- Privilege EscalationValid Accounts · Account Manipulation: Additional Cloud Credentials · Account Manipulation: Device Registration · Domain or Tenant Policy Modification: Group Policy Modification · Create or Modify System Process: Windows Service
- StealthValid Accounts · Hide Artifacts: Email Hiding Rules
- Defense ImpairmentDomain or Tenant Policy Modification: Group Policy Modification
- Credential AccessOS Credential Dumping: NTDS · Multi-Factor Authentication Interception · Steal Application Access Token · Adversary-in-the-Middle · Multi-Factor Authentication Request Generation
- Lateral MovementRemote Services: Remote Desktop Protocol · Remote Services: Windows Remote Management · Internal Spearphishing · Use Alternate Authentication Material: Application Access Token
- CollectionEmail Collection: Remote Email Collection · Adversary-in-the-Middle
- Command and ControlApplication Layer Protocol: Web Protocols · Web Service · Remote Access Tools
- ExfiltrationExfiltration Over Web Service
- ImpactData Encrypted for Impact
Reconnaissance TA0043
T1598Phishing for Information×1
Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Phishing for information is different from Phishing in that the objective is gathering data from the victim rather than executing malicious code.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Initial Access TA0001
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1566.002Phishing: Spearphishing Link×1
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit · ATT&CK page ↗
Persistence TA0003
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1098.001Account Manipulation: Additional Cloud Credentials×1
Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Evidence: 2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Privilege Escalation TA0004
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1098.001Account Manipulation: Additional Cloud Credentials×1
Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Evidence: 2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit · ATT&CK page ↗
T1098.005Account Manipulation: Device Registration×1
Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Stealth TA0005
T1078Valid Accounts×1
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1564.008Hide Artifacts: Email Hiding Rules×1
Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the <code>New-InboxRule</code> or <code>Set-InboxRule</code> PowerShell cmdlets on Windows systems.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Defense Impairment TA0112
T1484.001Domain or Tenant Policy Modification: Group Policy Modification×1
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path `\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Credential Access TA0006
T1003.003OS Credential Dumping: NTDS×1
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in <code>%SystemRoot%\NTDS\Ntds.dit</code> of a domain controller.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1111Multi-Factor Authentication Interception×1
Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1528Steal Application Access Token×1
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
Evidence: 2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1621Multi-Factor Authentication Request Generation×1
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Lateral Movement TA0008
T1021.001Remote Services: Remote Desktop Protocol×1
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1021.006Remote Services: Windows Remote Management×1
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1534Internal Spearphishing×1
After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user. Adversaries may then attempt to take advantage of the trusted internal account to increase the likelihood of tricking more victims into falling for phish attempts, often incorporating Impersonation.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1550.001Use Alternate Authentication Material: Application Access Token×1
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Evidence: 2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit · ATT&CK page ↗
Collection TA0009
T1114.002Email Collection: Remote Email Collection×1
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
Evidence: 2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit · ATT&CK page ↗
T1557Adversary-in-the-Middle×1
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1102Web Service×1
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Exfiltration TA0010
T1567Exfiltration Over Web Service×1
Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-29/talos-ir-trends-q2-2026-rmm-weaponization-auth-abuse · ATT&CK page ↗
Entries about ARToken (2)
Where this entity is cited
Source distribution
- blog.talosintelligence.com2 (67%)
- cyberscoop.com1 (33%)
All cited sources (3)
- blog.talosintelligence.comCisco Taloshttps://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/
- blog.talosintelligence.comCisco Talos Incident Responsehttps://blog.talosintelligence.com/ir-trends-q2-2026/
- cyberscoop.comCyberScoophttps://cyberscoop.com/artoken-bec-platform-cisco-talos/