Protect.Computer
NEWS

Phishing Kit Exposed That Clones Microsoft 365 Login Pages

· 1 min read · Digital scams Got hacked
Phishing Kit Exposed That Clones Microsoft 365 Login Pages

Security researchers have exposed a criminal tool called ARToken — part of a service also known as EvilTokens — that makes it easy for attackers to build fake login pages that look exactly like Microsoft 365, including Outlook and Teams. The criminals behind this send phishing emails to trick you into clicking a link that takes you to one of these convincing fakes. When you type in your email and password, they steal your credentials immediately. The kit is also designed to bypass two-factor authentication (2FA) by intercepting the verification codes in real time.

This type of attack is particularly dangerous because the fake pages are nearly indistinguishable from the real Microsoft login screen. Anyone who uses Microsoft 365 for work, school, or personal email is a potential target. The best defense is to be suspicious of any email that asks you to log in, regardless of how genuine it looks.

How to check if you’re affected

Affected products include all versions of Microsoft 365 and Microsoft Outlook — any account that logs in through a browser can be targeted, regardless of your subscription tier.

  1. Check your Microsoft account sign-in activity at account.microsoft.com/security. Look for any sign-ins from unfamiliar countries or devices.
  2. If you use a physical security key (like a YubiKey) instead of an SMS or app code for 2FA, you’re already protected against this specific attack — real-time interception doesn’t work against hardware keys.
  3. Never click “sign in” links in emails. Instead, open a new browser tab and go directly to outlook.com or your organization’s login page.

Sources

Related reading