'Ghost Phishing' Campaign Slips Past Email Filters by Hiding Until It Reaches the Victim
The EvilTokens operation is hitting companies across the US and Europe with pages that stay encrypted in transit and only unlock inside the target's browser.

Key points
- A phishing campaign called EvilTokens is targeting businesses in the United States and Europe with a technique researchers are calling 'ghost phishing'.
- Fake login pages arrive encrypted and only assemble themselves inside the victim's web browser, letting them slip past standard URL and email scanners.
- The main prize is Microsoft 365 credentials, opening a path into corporate email and internal files.
- Security teams say traditional link-checking tools cannot see the malicious content because it doesn't exist in a readable form until the page loads.
A fresh wave of phishing attacks is quietly picking off business accounts on both sides of the Atlantic, and the trick behind it is designed specifically to defeat the security scanners most companies rely on.
The campaign has been named EvilTokens by the researchers tracking it. First reported by The Hacker News, it is hitting targets across the United States and Europe. We first covered EvilTokens on 28 May 2026, and our 3 July report found more than 80 hidden commands inside the platform's phishing kit, including tools to read mailboxes and erase traces.
Phishing is when criminals send fake emails that trick staff into typing passwords into a lookalike website. It remains the most common way corporate networks get broken into.
What is 'ghost phishing' and why does it matter?
Ghost phishing keeps the malicious web page hidden during inspection. The page arrives scrambled and only unscrambles inside the victim's browser.
Think of it like a letter that looks blank when the post office X-rays it, but reveals its message only when the recipient holds it up to a specific lamp at home. By the time the words appear, the mail room has already waved it through.
Most email security products work by following links in a message and checking what is on the other end. If the page looks like a Microsoft login clone, the link gets blocked. Ghost phishing sidesteps that entirely, because at the moment of inspection there's nothing suspicious to see. The dangerous content is encrypted and only decrypts in the target's browser.
What are the attackers after?
Microsoft 365 credentials, mainly. That's the username and password staff use to sign in to Outlook and OneDrive.
Once criminals have a working login, they can read company email, download files, impersonate the account owner, and pivot to steal money through fake invoice requests. In many break-ins investigated over the past two years, a single stolen Microsoft 365 account was the starting point.
The campaign name, EvilTokens, hints at a further twist. Modern login systems issue small digital passes called tokens after you sign in, so you don't have to type your password again for a while. If attackers grab those tokens, they can stay logged in even after the victim changes their password.
What should ordinary staff watch for?
The usual signs still apply. An unexpected email asking you to log in to view a document, or a login page that appears after clicking a link rather than after you typed the address yourself.
If a Microsoft sign-in screen appears when you weren't trying to sign in, close the tab. Go to office.com by typing it directly. If there was a document waiting, it'll be there.
For security teams, the practical point is blunt. Link-scanning at the email gateway isn't enough on its own anymore. Detections that watch what happens inside the browser, and controls that flag unusual sign-in behaviour on Microsoft 365 accounts, are doing the heavier lifting now. Our 8 July story on why blocking phishing emails doesn't stop the underlying campaign sets out what disruption at source actually requires.
No victim companies have been publicly named. No extortion component has been tied to the campaign so far. The goal appears to be quiet account takeover, and quiet is what makes it worth watching.



