logo

New Ghost Phishing Wave Is Breaking Traditional Email Security

ID: 96078d2f-7168-5084-b626-a061d33b0d26

STIX ID: report--96078d2f-7168-5084-b626-a061d33b0d26

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-07-08

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

The report describes an ongoing EvilTokens "ghost phishing" campaign targeting organizations across the US and Europe—especially consulting, financial services, manufacturing, technology, banking, and MSSPs—where phishing pages are AES-GCM encrypted and only reveal a Microsoft Device Code login flow once decrypted in the victim's browser, enabling Microsoft 365 account takeover; ANY.RUN's interactive sandbox analysis exposed the decrypted DOM, associated HTTP requests, and produced IOCs and response guidance to close the browser-level visibility gap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.