{"id":1655,"date":"2026-07-08T14:07:40","date_gmt":"2026-07-08T14:07:40","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1655"},"modified":"2026-07-08T14:07:40","modified_gmt":"2026-07-08T14:07:40","slug":"new-ghost-phishing-wave-is-breaking-traditional-email-security","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1655","title":{"rendered":"New Ghost Phishing Wave Is Breaking Traditional Email Security"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgl6gaxMQBH0Bjb1ZhuaOiM5gKEk-zuSf821eRfV33ogx6YWwENunjyOPF8VXHtgtHgIevENLfBV2O04QI4TtjtDe2PGGevWptQEEagmp6q-G4FqOankGokz70XzVtz7dmNbEZ5G7-pV0yINgd2-ima7ap8xeOxuhZBKw2WPoUo81wKmGrwsPxbzYkW5Wk\/s1700-e365\/anyrun-main.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This \u201cghost phishing\u201d technique keeps the malicious page hidden until it decrypts and comes to life inside the victim\u2019s browser.<\/p>\n<p>For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time are already at stake.<\/p>\n<h2>The Email Looks Safe. The Browser Tells a Different Story<\/h2>\n<p>A recent EvilTokens attack shows how a phishing link can appear harmless during initial inspection while still leading to Microsoft 365 account takeover.<\/p>\n<p>The kit uses Microsoft Device Code Phishing to convince victims to complete a legitimate Microsoft login flow and unknowingly authorize access to their accounts. It does not need to steal the password directly.<\/p>\n<p>The real attack remains hidden until the page opens in the browser. Its HTML is encrypted with AES-GCM and becomes visible only after the browser decrypts it and renders the phishing content in the DOM.<\/p>\n<p>As a result, static URL checks and network-level controls may capture the initial response without seeing what the employee actually sees. This visibility gap can lead to:<\/p>\n<ul>\n<li><strong>Longer exposure<\/strong> to the Microsoft 365 account takeover<\/li>\n<li><strong>Delayed containment<\/strong> and response decisions<\/li>\n<li><strong>Unauthorized access<\/strong> to corporate email, files, and cloud services<\/li>\n<li>More uncertain <strong>alerts escalated<\/strong> to senior analysts<\/li>\n<li>Higher investigation <strong>workload and operational costs<\/strong><\/li>\n<li><strong>Incomplete evidence<\/strong> for blocking related infrastructure<\/li>\n<\/ul>\n<p>The complete attack flow, however, was uncovered inside ANY.RUN\u2019s Interactive Sandbox. Explore the analysis session to see what the browser revealed and how teams can use this evidence to respond faster.<\/p>\n<p><a href=\"https:\/\/app.any.run\/tasks\/55d3ead7-c07a-4fb1-aa42-8c397d1a0f8a?utm_source=thehackernews&amp;utm_medium=article&amp;utm_campaign=ghost_phishing&amp;utm_content=task&amp;utm_term=080726\" target=\"_blank\">Check recent EvilTokens attack and get relevant IOCs<\/a><\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEifPPxwUNUUdcSUjFFwXjrkpJP3q8gjx-hpOGomTjEMRiOSqIZ61nbIhWyT9GI7M086X9XcjGCoLT51rfER_hUAKkDIWpz9h7zWwadQTw1dkNQeIujdiZT4fkD7wWwajVjF-_y6z4mDv8CTjIqdRZUi51uIX5j0OSwIazFz1yWXmy6PQZFzMVaAawWh611W\/s1700-e365\/any-1.jpg\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEifPPxwUNUUdcSUjFFwXjrkpJP3q8gjx-hpOGomTjEMRiOSqIZ61nbIhWyT9GI7M086X9XcjGCoLT51rfER_hUAKkDIWpz9h7zWwadQTw1dkNQeIujdiZT4fkD7wWwajVjF-_y6z4mDv8CTjIqdRZUi51uIX5j0OSwIazFz1yWXmy6PQZFzMVaAawWh611W\/s1700-e365\/any-1.jpg\" alt=\"\" border=\"0\" data-original-height=\"1139\" data-original-width=\"2048\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Complicated ghost phishing revealed inside ANY.RUN\u2019s sandbox<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Where Ghost Phishing Is Hitting Hardest<\/h2>\n<p>ANY.RUN\u2019s Threat Intelligence shows recent EvilTokens activity concentrated across the US and Europe, targeting technology, manufacturing, education, banking, consulting, financial services, and managed security providers.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsS4RnFvKBFIdAT5bIOfeYQPD2bi5f7zPEHhgk3nSVekf0S3nfCjfYxS8qJ_zkRHJR5iY7BKlw8TF3RCXpHzCVEGNxiwLjUpdFLy7Dkm-yNlsk_rvUGABUVAGrP0GZ71OYQ3Llo6mhrQl-KY93H_f-SbYU-2oj-vn5mUmPkJqjPVcukIHbkbxqheCLvxGB\/s1700-e365\/any-2.jpg\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsS4RnFvKBFIdAT5bIOfeYQPD2bi5f7zPEHhgk3nSVekf0S3nfCjfYxS8qJ_zkRHJR5iY7BKlw8TF3RCXpHzCVEGNxiwLjUpdFLy7Dkm-yNlsk_rvUGABUVAGrP0GZ71OYQ3Llo6mhrQl-KY93H_f-SbYU-2oj-vn5mUmPkJqjPVcukIHbkbxqheCLvxGB\/s1700-e365\/any-2.jpg\" alt=\"\" border=\"0\" data-original-height=\"1434\" data-original-width=\"2048\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">ANY.RUN\u2019s TI shows threat activity targeting specific regions<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The overlap is hard to ignore. Based on ANY.RUN\u2019s sandbox submissions data from 15,000 organizations, phishing exposure in 2026 reached <strong>75.6% in consulting, 72.8% in financial services, 71.9% in manufacturing, 67.9% in technology, 66.7% in banking, and 66.1% among MSSPs<\/strong>.<\/p>\n<p>This makes hidden phishing especially dangerous for these sectors. One compromised Microsoft 365 account can expose sensitive data, enable business email compromise and fraud, and trigger costly incident response.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The longer the attack stays hidden, the greater the chance that one account becomes a wider business incident.<\/p>\n<div class=\"article-board\">\n<p><strong>Stop hidden phishing before it costs your business.<\/strong><\/p>\n<p>Reduce exposure, incident costs, and account takeover risk.<\/p>\n<p><a href=\"https:\/\/any.run\/enterprise\/?utm_source=thehackernews&amp;utm_medium=article&amp;utm_campaign=ghost_phishing&amp;utm_content=enterprise&amp;utm_term=080726#contact-sales\" target=\"_blank\">Close Visibility Gap<\/a><\/p>\n<\/div>\n<h2>Make the Ghost Visible Before the Business Pays the Price\u00a0<\/h2>\n<p>The most effective way to expose ghost phishing is to open suspicious links in a sandbox that supports in-browser data inspection.<\/p>\n<p>Inside ANY.RUN\u2019s Interactive Sandbox, analysts move beyond the encrypted AES-GCM response and see what happens after the page decrypts. They can watch the phishing content appear in the DOM, connect the change to a Fetch\/XHR request, and trace the Microsoft device code back to the \/api\/device\/start endpoint.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEii92diC7QiJevKW3lj8HsoFIVrY_VotnnJuEtAXrzzsQastnjqSYt0pC6_SwYPffiWonsEzi2sd9wWbcRIZyOpjhxwQjJbx5WObWLC0W6PHFt7JP8gFTYs9veKSm3abNjN_goqdCCFsPFgV7KhxMZ2arQk9pSUoVMf_dQGcnMS18_y__mszCDontPO4WD5\/s1700-e365\/any-3.jpg\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEii92diC7QiJevKW3lj8HsoFIVrY_VotnnJuEtAXrzzsQastnjqSYt0pC6_SwYPffiWonsEzi2sd9wWbcRIZyOpjhxwQjJbx5WObWLC0W6PHFt7JP8gFTYs9veKSm3abNjN_goqdCCFsPFgV7KhxMZ2arQk9pSUoVMf_dQGcnMS18_y__mszCDontPO4WD5\/s1700-e365\/any-3.jpg\" alt=\"\" border=\"0\" data-original-height=\"1765\" data-original-width=\"2048\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">The decrypted HTML DOM viewed in the in-browser data investigation panel<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The in-browser data view brings the full attack flow into one investigation:<\/p>\n<ul>\n<li>DOM snapshots show when the hidden page changes and the user code appears.<\/li>\n<li>HTTP requests reveal the backend communication behind the device-code flow.<\/li>\n<li>URL details expose the final destination and triggered detection signatures.<\/li>\n<li>Indicators provide domains, endpoints, hashes, and infrastructure for further hunting.<\/li>\n<\/ul>\n<p>Instead of reconstructing the attack manually, teams get direct evidence of how the page behaves, what it requests, and which artifacts support containment and detection.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgYpmggNWnUDGedq2nqv85bOdY2fgoeFaIu3aqz2qOOJyEJZ0egB_QlCyaosyJCgmpCd2_cV-vtbQCqdJEbtqn8UalPkA10gWCKur-BOF8Ev-gQbwrSmOeRgOKevtOopMusPl0hWudtsKHAsQsuq5ZjH6ykvKJVW__SN5WjVaQdD2bCCG-S1M8peLgRFEJY\/s1700-e365\/any-4.jpg\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgYpmggNWnUDGedq2nqv85bOdY2fgoeFaIu3aqz2qOOJyEJZ0egB_QlCyaosyJCgmpCd2_cV-vtbQCqdJEbtqn8UalPkA10gWCKur-BOF8Ev-gQbwrSmOeRgOKevtOopMusPl0hWudtsKHAsQsuq5ZjH6ykvKJVW__SN5WjVaQdD2bCCG-S1M8peLgRFEJY\/s1700-e365\/any-4.jpg\" alt=\"\" border=\"0\" data-original-height=\"558\" data-original-width=\"1352\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">DOM snapshots displaying the decrypted code<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>From Browser-Level Evidence to a Clearer SOC Handoff<\/h2>\n<p>To carry this evidence from Tier 1 to Tier 2, the investigation automatically generates a report with an AI summary and recommended next steps.<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhIR88ZECsNM0vMZb37BM7dJ9A_bTSCBXP-6wsa_5QOW2IY_2vbTLQJnw4ZsWuUl_OVechF_SiPUqmp0Cwb4QUO7WrJfqrxsSDaHzc8Hiud8X0lUaBr_lc1r6gV7mV66E8oMh50WcDz4RhXgXxU-BTCgOgHkDJ_YAmYtbEQqyyrKAUS4eFrXt6wfz90EyIA\/s1700-e365\/any-5.jpg\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhIR88ZECsNM0vMZb37BM7dJ9A_bTSCBXP-6wsa_5QOW2IY_2vbTLQJnw4ZsWuUl_OVechF_SiPUqmp0Cwb4QUO7WrJfqrxsSDaHzc8Hiud8X0lUaBr_lc1r6gV7mV66E8oMh50WcDz4RhXgXxU-BTCgOgHkDJ_YAmYtbEQqyyrKAUS4eFrXt6wfz90EyIA\/s1700-e365\/any-5.jpg\" alt=\"\" border=\"0\" data-original-height=\"921\" data-original-width=\"1376\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">Auto-generated report from EvilTokens analysis session<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Instead of rebuilding the case from raw browser data, senior analysts receive the key findings, observed behavior, indicators, and response context in one place. This makes handoffs faster, reduces repeated work, and helps teams move from validation to containment with less delay.<\/p>\n<h2>Stop Ghost Phishing in the Browser Before It Reaches the Business<\/h2>\n<p>The EvilTokens case exposes an uncomfortable truth: an email can pass inspection while the real attack waits inside the browser.<\/p>\n<p>Without browser-level visibility, the SOC is forced to make high-stakes decisions with partial evidence. That delay gives attackers more time to gain access, expand their reach, and turn one compromised Microsoft 365 account into a costly business incident.<\/p>\n<p>This helps security leaders:<\/p>\n<ul>\n<li><strong>Shrink the exposure window<\/strong> before a compromised account becomes a wider incident<\/li>\n<li><strong>Reduce pressure on senior analysts<\/strong> by giving Tier 1 enough evidence to resolve more cases<\/li>\n<li><strong>Accelerate containment<\/strong> with complete attack context available from the first escalation<\/li>\n<li><strong>Improve detection coverage<\/strong> using browser behavior, infrastructure, and repeatable attack patterns<\/li>\n<li><strong>Lower the cost of phishing response<\/strong> by cutting manual investigation and duplicated work<\/li>\n<li><strong>Make risk decisions with evidence<\/strong> instead of relying on clean scans or inconclusive verdicts<\/li>\n<\/ul>\n<p>Modern phishing no longer reveals itself fully in the email or initial URL response. Security teams need visibility that follows the attack into the browser and exposes it before the business pays the price.<\/p>\n<p><strong><a href=\"https:\/\/any.run\/enterprise\/?utm_source=thehackernews&amp;utm_medium=article&amp;utm_campaign=ghost_phishing&amp;utm_content=enterprise&amp;utm_term=080726#contact-sales\" target=\"_blank\">Reduce business exposure<\/a>:<\/strong> Give analysts full browser evidence to contain ghost phishing faster and stop one compromised account from escalating into a costly incident.<\/p>\n<div class=\"cf note-b\">Found this article interesting? <span class=\"\">This article is a contributed piece from one of our valued partners.<\/span> Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ\" rel=\"noopener\" target=\"_blank\">Google News<\/a>, <a href=\"https:\/\/twitter.com\/thehackersnews\" rel=\"noopener\" target=\"_blank\">Twitter<\/a> and <a href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" rel=\"noopener\" target=\"_blank\">LinkedIn<\/a> to read more exclusive content we post.<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This \u201cghost phishing\u201d technique keeps the malicious page hidden until it&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1656,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2408,954,849,390,47,2413,386],"class_list":["post-1655","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-breaking","tag-email","tag-ghost","tag-phishing","tag-security","tag-traditional","tag-wave"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1655"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1655\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1656"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}