As cited
Copy frozen at (site build).
threat intel
New Ghost Phishing Wave Is Breaking Traditional Email Security
A new phishing campaign called EvilTokens uses encrypted payloads that remain hidden from email security scanning until they decrypt in the victim's browser, bypassing traditional URL-based detection. This technique targets businesses in the US and Europe, potentially exposing Microsoft 365 accounts and sensitive data to compromise.
Why it matters: Email security teams and Microsoft 365 defenders need to evaluate detection gaps for encrypted phishing payloads, as traditional gateway and URL filtering may fail to catch these attacks before they reach end users.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
New Ghost Phishing Wave Is Breaking Traditional Email Security
A new phishing campaign called EvilTokens uses encrypted payloads that remain hidden from email security scanning until they decrypt in the victim's browser, bypassing traditional URL-based detection. This technique targets businesses in the US and Europe, potentially exposing Microsoft 365 accounts and sensitive data to compromise.
Why it matters: Email security teams and Microsoft 365 defenders need to evaluate detection gaps for encrypted phishing payloads, as traditional gateway and URL filtering may fail to catch these attacks before they reach end users.
- Source published
- First seen by Cybersecurity Tracker