
Ghost Phishing: When a Clean Scan Is Not a Clean Page
You forwarded the link to your IT team and the reply came back within seconds. Scanned, clean, nothing found. So you clicked it. What you could not have known is that the page was still asleep. The dangerous part had not loaded yet, and it would not load until the link reached the one place your security tools were not looking: the inside of your own browser.
Ghost phishing is a technique where the malicious web page arrives encrypted and only decrypts once it renders in the victim's browser. Because email filters and URL scanners inspect a link before that moment, they see nothing harmful and wave it through. A phishing kit called EvilTokens has been doing exactly this across the United States and Europe to take over Microsoft 365 accounts, according to analysis reported in July 2026.
Why did the scanner say the link was safe?
When a security tool checks a link, it fetches the page and reads what comes back. For most phishing, that is enough. The fake login form, the dodgy script, the redirect to a lookalike domain, it all sits there in the response for a scanner to find.
Ghost phishing changes what comes back. The harmful HTML is scrambled using AES-GCM encryption, a standard, legitimate way of protecting data. To a scanner, the response looks like a meaningless block of characters with nothing to flag. The key that unscrambles it only runs when a real browser loads the page, at which point the phishing content is decrypted and written into the page for the person to see. The scanner saw the locked box. You were handed the box and the key together.
This is why a clean verdict means less than it used to. The check happened at the door. The attack was waiting in the room.
What is the page actually after?
Here is the first surprise. It is not chasing your password. Once the EvilTokens page comes to life, it walks you into a genuine Microsoft sign-in using something called the device code flow. No fake login screen, no cloned Microsoft page harvesting your details. Everything you touch really is Microsoft.
The device code flow exists for a good reason. It lets you sign in on gadgets that are awkward to type on, a smart TV or a printer, by showing a short code and asking you to enter it on your phone or laptop instead. Microsoft itself now treats it as a high-risk flow that attackers abuse, because the same convenience can be turned against the person using it.
How can a short code hand over your whole account?
The attacker starts a real sign-in to Microsoft from their own machine. Microsoft hands back a short device code, valid for a few minutes. The attacker then delivers that code to you, wrapped in a message that feels routine, a document to review, a meeting to confirm, an account to verify. You are asked to visit the genuine Microsoft page and type the code in.
So you do. You are on the real site. You complete multi-factor authentication yourself, because it is your account and your approval. The moment you finish, Microsoft grants the waiting session on the attacker's machine. They now hold a valid token for your account, often including a refresh token that keeps working long after you have closed the tab.
The part that catches people out
Most of us picture phishing as a fake page that tricks a secret out of us. Ghost phishing does not need the secret. You were never asked to reveal your password, so nothing felt like it was being stolen. And multi-factor authentication did not save you, because you passed it. You were not fooled into giving something away. You were fooled into granting permission.
Think of it as being handed a genuine visitor form at a real reception desk and asked to sign. The form is real, the pen is yours, the desk is exactly where it should be. The only thing wrong is who is standing behind you, waiting to walk in wearing the badge you just authorised.

Who is being hit
The sandbox firm that documented the campaign, ANY.RUN, says its data from roughly 15,000 organisations shows heavy phishing exposure across consulting, financial services, manufacturing, technology and banking, alongside managed service providers. Those are its own figures rather than an industry-wide count, so treat them as a signal of where this is landing. The pattern is what matters. One taken-over Microsoft 365 account opens the door to email, files, and the trust of everyone who knows that address, which is how a single click becomes invoice fraud or a wider breach.
What to do about it
For individuals, the rule is refreshingly simple. A genuine Microsoft prompt only appears because you started signing in. If a message, a colleague, or a support call asks you to enter a code you did not request, or to approve a sign-in you did not begin, stop there. That is the whole trick in a sentence, and it holds even when the page in front of you is completely real. When something feels slightly off, report it. A reported message that turns out to be nothing costs a moment. A silent one can cost far more.
For organisations, treat the email gateway as one layer rather than the answer. Some of these links will reach people, so the goal is to make the human step safe. Microsoft lets you block the device code flow with a Conditional Access policy and recommends getting as close to a full block as your legitimate uses allow. Audit where the flow is genuinely needed, shut it everywhere else, and keep token lifetimes tight so a stolen session does not last. Then teach the one thing that defeats this attack: never enter a code or approve a sign-in you did not personally start. People are a defence layer worth equipping, and here they are the layer that actually works.
Key takeaways
- Ghost phishing hides its payload with AES-GCM encryption and only decrypts inside the browser, so email and URL scanners can pass it as clean.
- The EvilTokens campaign uses this to run Microsoft's device code flow, not to steal passwords.
- You approve the attacker's session yourself on the real Microsoft site, which is why completing MFA does not stop it.
- Individuals should never enter a code or approve a sign-in they did not personally begin.
- Organisations should block or tightly limit the device code flow with Conditional Access and keep session tokens short-lived.
Frequently asked questions
Does this mean my email security is useless?
No. Filters still stop the large volume of ordinary phishing. Ghost phishing is a reminder that no single gate catches everything, so the person on the other side of the link needs to know what a safe request looks like.
If I never typed my password, is my account safe?
Not necessarily. The attacker gains access by holding a valid session token, not your password. Changing your password may not end their access, so revoke active sessions and sign-in tokens and tell your IT team straight away.
Would multi-factor authentication have protected me?
Not on its own. You complete MFA as part of the real sign-in, and that approval is exactly what the attacker is waiting for. MFA still matters everywhere else, but this attack is designed to ride on top of it.
How do I spot a device code request that is a trap?
Ask one question: did I start this? A real device code prompt only shows up because you began signing in on another gadget. If a code arrives out of the blue, or someone asks you to enter one, that is your cue to stop and report it.
Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.
Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.
