ARToken PhaaS C2 Infrastructure Investigation — Live Threat Actor DFIR Report

Full DFIR investigation of the ARToken/EvilTokens Phishing-as-a-Service C2 infrastructure. Step-by-step probe methodology, live API surface mapping, TLS forensics, WHOIS pivots, and 80+ endpoint extraction from a fully operational threat actor panel.

2026-08-31T22:42:37.913Z
Rudra Verma, Senior Security Architect & Researcher