hacker-news · Crawled Jul 8, 2026
New Ghost Phishing Wave Is Breaking Traditional Email Security
1 IoCs
Read original article ↗
AI Summary
A new 'ghost phishing' campaign dubbed EvilTokens is targeting businesses in the US and Europe, leveraging encrypted HTML content that remains hidden until decrypted in the browser. This technique bypasses traditional email and URL security checks, enabling Microsoft 365 account takeover via legitimate Microsoft login flows without directly stealing passwords. The attack exploits browser-level decryption to reveal phishing content post-load, making detection more difficult and increasing the risk of unauthorized access to sensitive data and cloud services.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | api/device/start | Details → |