Skip to main content
Back to Newswire
Security

New Ghost Phishing wave via EvilTokens campaign is breaking traditional email security

New Ghost Phishing wave via EvilTokens campaign is breaking traditional email security Image: Primary
A recent EvilTokens phishing campaign targeting businesses in the United States and Europe is using a method The Hacker News describes as "ghost phishing," according to a July 8, 2026 report on the site that draws on analysis from security firm ANY.RUN. The report says the technique keeps a malicious page hidden until it decrypts and loads inside a victim's browser. Phishing kit HTML is encrypted with AES-GCM and becomes visible only after the browser decrypts it and renders the content in the DOM, so static URL checks and network-level controls may not see what the user sees, The Hacker News reported. According to the article, the kit uses Microsoft Device Code Phishing to push victims through a legitimate Microsoft login flow that can authorize access to Microsoft 365 accounts without directly stealing a password. ANY.RUN's threat intelligence, as cited by The Hacker News, shows recent EvilTokens activity concentrated in the U.S. and Europe against sectors including technology, manufacturing, education, banking, consulting, financial services and managed security providers. ANY.RUN sandbox data from 15,000 organizations found 2026 phishing exposure of 75.6% in consulting, 72.8% in financial services, 71.9% in manufacturing, 67.9% in technology, 66.7% in banking and 66.1% among MSSPs, the report said. The full attack flow was observed in ANY.RUN's Interactive Sandbox, according to The Hacker News.
Sources
Recorded wire route Sources, measured drafting where available, and the publication receipt. See concurrent Machine
Evidence entered
Admission Evidence and chronology passed Security
Publication receipt Entered the validated Newswire
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire