EvilTokens Campaign Unveils New Email Security Vulnerabilities
A recent series of attacks by the EvilTokens campaign has spotlighted a significant blind spot in email security protocols, primarily affecting businesses across the United States and Europe. This tactic, sometimes referred to as “ghost phishing,” cleverly obscures malicious webpages until they are decrypted and unveiled within victims’ browsers. As this method evolves, security leaders must recognize that traditional URL checks may not adequately detect such sophisticated threats.
In these attacks, attackers utilize Microsoft Device Code Phishing to dupe users into entering their credentials through a legitimate-looking Microsoft login interface. By avoiding direct password theft, attackers exploit trust and psychological tactics to gain unauthorized access. The true nature of the phishing attack remains hidden until the user engages with the page in their browser—wherein the malicious HTML, encrypted using AES-GCM, becomes visible only after decryption and rendering.
This concealed nature of the attack highlights a critical vulnerability in static URL checks and network defenses. Security systems may recognize initial threats but fail to capture the actual content presented to employees, creating a visibility gap that can lead to longer exposure times for compromised accounts, delayed responses from security teams, and unauthorized access to sensitive corporate assets.
Data from ANY.RUN’s Interactive Sandbox illustrates the complete attack flow, offering insights that security teams can leverage for quicker response times. Analysts can observe the unfolding of the attack, connecting it to specific Fetch/XHR requests and tracing the Microsoft device code back to its origins, all within a secure, isolated environment.
The impact of the EvilTokens attacks has predominantly affected sectors such as technology, manufacturing, education, banking, consulting, and financial services. Threat intelligence indicates a concerning surge in phishing exposure, with figures suggesting that 75.6% of consulting firms and 72.8% of financial service providers have been targeted. One compromised Microsoft 365 account could cascade into broader breaches, exposing sensitive data and leading to costly operational consequences.
As organizations are increasingly equipped with advanced tools to combat phishing, the tactics employed in the EvilTokens campaign remind security leaders of the persistent need for enhanced visibility into browser-level threats. Existing defenses may allow email-based attacks to slip through, while real threats linger behind the curtain of the browser interface.
To effectively combat such threats, organizations should consider implementing sandbox environments that allow for the inspection of in-browser data in real time. By harnessing such tools, security analysts can detect the encrypted HTML changes, observe the user interaction, track backend communications, and gather actionable indicators for further investigation.
Ultimately, this evolving landscape of phishing attacks demands a proactive approach to cybersecurity. As traditional defenses may falter, organizations must close gaps in their visibility and response strategies. Enhancing detection capabilities and empowering resources with comprehensive evidence can limit the impact of these sophisticated attacks before they escalate into larger business incidents.
As the threat of ghost phishing looms, business owners must take heed and ensure that their cybersecurity strategies evolve in line with emerging threats. A vigilant approach to browser-level security will not only reduce risks but also protect critical assets from the insights gleaned from evolving tactics outlined in frameworks such as the MITRE ATT&CK Matrix.