news.mlab.sh
Back to the feed
threat-intel

New Ghost Phishing Wave Is Breaking Traditional Email Security

High
Image: The Hacker News
Summary

A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign, targeting businesses across the US and Europe, leverages Microsoft Device Code Phishing to gain access to Microsoft 365 accounts without directly stealing passwords. This technique is particularly dangerous for sectors like technology, manufacturing, and managed security providers, where phishing exposure is already high. ANY.RUN’s Interactive Sandbox provides a method to expose these hidden attacks by revealing the full attack flow within the browser, enabling faster investigation and containment.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.