A recent wave of EvilTokens attacks is exposing a blind spot in email security. Dubbed “ghost phishing,” the technique keeps malicious content hidden until the page decrypts inside the victim’s browser.
Static URL checks and network-level controls catch the initial response — but they never see what the employee actually sees.
Here’s how it works. The phishing link uses Microsoft Device Code Phishing. Victims are tricked into completing a legitimate Microsoft login flow, unknowingly authorizing the attacker to access their account. No password theft required.
The real payload is encrypted with AES-GCM in the HTML. It only becomes visible after the browser decrypts and renders it in the DOM. Traditional email scanners see a harmless blob. Users see a convincing Microsoft login page.
The result? Longer exposure to account takeover, delayed containment, and incomplete evidence for blocks.
The campaign targets businesses across the US and Europe — tech, manufacturing, education, banking, consulting, financial services, and managed security providers. ANY.RUN’s threat intel shows these sectors have phishing exposure rates as high as 75.6% in consulting and 72.8% in financial services.
One compromised Microsoft 365 account can expose sensitive data, enable business email compromise, and trigger expensive incident response.
The fix? Open suspicious links in a sandbox that supports in-browser data inspection. Tools like ANY.RUN’s Interactive Sandbox let analysts see what happens after the page decrypts — watching the phishing content appear in the DOM, tracing the device code flow, and extracting indicators for hunting. That’s the difference between guessing and knowing.
