EvilTokens, a device-code phishing kit capable of bypassing multi-factor authentication on Microsoft 365, has been found to be more sophisticated than previously understood, with Cisco Talos uncovering a linked phishing-as-a-service operator panel called "ARToken." Talos revealed how the phishing lures reach victims' inboxes, describing a targeted approach that exploits real vendor relationships and abuses legitimate SharePoint domains to evade detection. Beyond simple credential theft, ARToken includes a comprehensive post-exploitation toolkit with full business email compromise capabilities, making it a complete BEC operations platform rather than just a phishing kit.