EvilTokens

☆ pin
Also known as ARToken
Reports
11
First seen
Mar 23, 2026
Last seen
Jul 31, 2026
Motivation
Financial

Relationships

Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.

Targeting

Victim regions
×2
×2
United States×2

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1566 Phishing ×10T1110 Brute Force ×6T1078 Valid Accounts ×5T1528 Steal Application Access Token ×4T1021.001 Remote Services: Remote Desktop Protocol ×3T1187 Forced Authentication ×3T1550.001 Use Alternate Authentication Material: Application Access Token ×3T1598 Phishing for Information ×2T1583.006 Acquire Infrastructure: Web Services ×2T1021.002 Remote Services: SMB/Windows Admin Shares ×2T1566.002 Phishing: Spearphishing Link ×2T1621 Multi-Factor Authentication Interception ×2

Indicators

domain ×24ip_v4 ×22ip_v6 ×1

Indicator values are available on Pro and via the API.

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.