New Ghost Phishing Wave Is Breaking Traditional Email Security
A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign, targeting businesses across the US and Europe, leverages Microsoft Device Code Phishing to gain access to Microsoft 365 accounts without directly stealing passwords. This technique is particularly dangerous for sectors like technology, manufacturing, and managed security providers, where phishing exposure is already high. ANY.RUN’s Interactive Sandbox provides a method to expose these hidden attacks by revealing the full attack flow within the browser, enabling faster investigation and containment.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
