New Ghost Phishing Wave Is Breaking Traditional Email Security
ID: 96078d2f-7168-5084-b626-a061d33b0d26
STIX ID: report--96078d2f-7168-5084-b626-a061d33b0d26
Feed Name: The Hacker News
The report describes an ongoing EvilTokens "ghost phishing" campaign targeting organizations across the US and Europe—especially consulting, financial services, manufacturing, technology, banking, and MSSPs—where phishing pages are AES-GCM encrypted and only reveal a Microsoft Device Code login flow once decrypted in the victim's browser, enabling Microsoft 365 account takeover; ANY.RUN's interactive sandbox analysis exposed the decrypted DOM, associated HTTP requests, and produced IOCs and response guidance to close the browser-level visibility gap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
