EvilTokens Attack Group Uses Ghost Phishing for Microsoft 365 Account Takeover
July 8, 2026
EvilTokens is an attack group conducting ghost phishing campaigns targeting US and European businesses. They use Microsoft Device Code Phishing and AES-GCM encryption to hide malicious content until it decrypts in the victim's browser, bypassing traditional email security.