ARToken PhaaS C2 Infrastructure: Live Threat Actor Investigation Report
Step-by-step DFIR investigation of the ARToken/EvilTokens Phishing-as-a-Service platform. Our probe confirms the C2 at spx.pamconj.com is fully operational — actively generating Microsoft device codes for live phishing campaigns. 80+ API endpoints mapped. Full evidence chain documented.
Rudra Verma, Senior Security Architect & Researcher