New Ghost Phishing Wave Evades Traditional Email Security
A new EvilTokens campaign uses ghost phishing to bypass traditional email security by hiding malicious pages until decrypted inside a victim’s browser. This poses high risk to businesses using Microsoft 365 and handling sensitive data.
Why it matters
This attack exposes a critical blind spot in traditional URL-based phishing detection.
SOC impact
SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.
Recommended actions
- Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
- Search for indicators associated with the described phishing or intrusion techniques.
- Brief analysts and help desk teams on the reported threat to improve detection and response.
Executive Summary
A new EvilTokens campaign uses ghost phishing to bypass traditional email security by hiding malicious pages until decrypted inside a victim’s browser. This poses high risk to businesses using Microsoft 365 and handling sensitive data. This attack exposes a critical blind spot in traditional URL-based phishing detection.
SOC Impact
SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.
Detection and Hunting Focus
- Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
- Search for indicators associated with the described phishing or intrusion techniques.
- Brief analysts and help desk teams on the reported threat to improve detection and response.
Why It Matters
This attack exposes a critical blind spot in traditional URL-based phishing detection.