ARToken PhaaS C2 Infrastructure: Live Threat Actor Investigation Report

Step-by-step DFIR investigation of the ARToken/EvilTokens Phishing-as-a-Service platform. Our probe confirms the C2 at spx.pamconj.com is fully operational — actively generating Microsoft device codes for live phishing campaigns. 80+ API endpoints mapped. Full evidence chain documented.

2026-07-27T00:43:49.654Z
Rudra Verma, Senior Security Architect & Researcher