A recent EvilTokens campaign is exploiting a new ‘ghost phishing’ technique that hides malicious content until it decrypts inside the victim’s browser, bypassing traditional email security checks. The attack uses Microsoft Device Code Phishing to trick users into authorizing access to their Microsoft 365 accounts without stealing passwords directly. The phishing page’s HTML is encrypted with AES-GCM and only becomes visible after browser decryption, making static URL inspections ineffective.
ANY.RUN’s Threat Intelligence reveals concentrated activity across the US and Europe, targeting technology, manufacturing, education, banking, consulting, financial services, and managed security providers. Based on sandbox submissions from 15,000 organizations, phishing exposure in 2026 reached 75.6% in consulting, 72.8% in financial services, 71.9% in manufacturing, 67.9% in technology, 66.7% in banking, and 66.1% among MSSPs.
The article highlights how ANY.RUN’s Interactive Sandbox can expose ghost phishing by allowing analysts to see the decrypted content in the browser DOM, trace Fetch/XHR requests, and identify Microsoft device code endpoints. This browser-level visibility helps security teams shrink exposure windows, reduce analyst workload, accelerate containment, and improve detection coverage.
CVEs: CVE-2026-55200, CVE-2026-46817
Attack groups: EvilTokens
Products: ANY.RUN Interactive Sandbox, Microsoft 365
Original source: thehackernews.com