New Ghost Phishing Wave Is Breaking Traditional Email Security
Frames ghost phishing as a newly discovered, technically sophisticated threat that exposes systemic limitations in existing email security — positioning detection failure as inherent to legacy methods rather than vendor-specific shortcomings.
View original on thehackernews.comOverview
A new 'ghost phishing' technique used in an EvilTokens campaign evades traditional email security by delaying malicious payload decryption until execution inside the victim's browser, creating a detection gap for URL-based filters.
TL;DR
- Ghost phishing hides malicious content until runtime in the browser, bypassing static URL scanning.
- The EvilTokens campaign targets businesses in the US and Europe using this method.
- Traditional email security tools like URL reputation checks may fail to detect these attacks.
Key Stats
US and Europe
geographic scope
Target regions of the EvilTokens campaign
Questions Answered
Keywords
Narrative Frame
breakthrough framing
Spin Score
75%
Emphasizes novelty and inevitability of evasion while minimizing evidence of real-world impact, scale, or independent verification; deflects scrutiny from specific vendor capabilities by generalizing 'traditional URL checks' as obsolete.
What the story wants you to believe
That 'ghost phishing' is a meaningful, emergent category of attack requiring urgent attention and new detection paradigms.
What it makes harder to question
Whether this technique is genuinely novel, operationally significant, or materially different from known obfuscation tactics used in prior phishing campaigns.
How the spin works
It combines naming authority ('ghost phishing'), vendor-agnostic problem framing ('traditional URL checks may miss'), and urgency language ('risk is clear') to inflate perceived novelty and inevitability — while the core claim rests entirely on unverified descriptive text, with no empirical validation or comparative analysis to distinguish it from longstanding JavaScript-based evasion.
Who Benefits If This Frame Spreads
Security research team behind the EvilTokens analysis
Credibility and thought leadership as discoverers of a novel attack vector
Naming and framing 'ghost phishing' establishes conceptual ownership and positions their methodology as essential for next-gen detection.
The Frame
Cutting-edge threat discovery revealing foundational gaps in enterprise security infrastructure.
Missing Context
- No details on mitigation efficacy, false positive rates of proposed alternatives, or comparative testing against commercial EDR/XDR platforms.
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The article presents a newly named attack method as a breakthrough threat — making it feel like a major evolution in phishing, even though it offers no proof of scale, uniqueness, or real-world impact beyond one campaign.
- Claim
This 'ghost phishing' technique keeps the malicious page hidden until
This 'ghost phishing' technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.
- Frame
Upside framed as transformative
Cutting-edge threat discovery revealing foundational gaps in enterprise security infrastructure.
- Beneficiary
Credibility and thought leadership as discoverers of a novel attack
Security research team behind the EvilTokens analysis — Credibility and thought leadership as discoverers of a novel attack vector
- Gap
No details on mitigation efficacy, false positive rates of proposed
No details on mitigation efficacy, false positive rates of proposed alternatives, or comparative testing against commercial EDR/XDR platforms.
- AI Risk
AI may repeat the headline as fact
Ghost phishing is a new email attack that hides malicious pages until they decrypt in the browser, bypassing traditional URL security.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| This 'ghost phishing' technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. | Descriptive assertion only; no code, packet capture, sandbox video, or forensic artifact cited. | Needs Evidence | High | Browser console logs showing delayed decryption; Side-by-side comparison of detection rates between URL scanners and behavioral analyzers; Independent replication report from another security lab |
This 'ghost phishing' technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.
evidence: Descriptive assertion only; no code, packet capture, sandbox video, or forensic artifact cited.
"This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser."
Evidence Gaps
- Browser console logs showing delayed decryption
- Side-by-side comparison of detection rates between URL scanners and behavioral analyzers
- Independent replication report from another security lab
Fact Check Signals
0 of 1 claim matched · confidence: low · checked July 9, 2026
This 'ghost phishing' technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
New Ghost Phishing Wave Is Breaking Traditional Email Security
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Cutting-edge threat discovery revealing foundational gaps in enterprise security infrastructure.
Media / Reader Counter-Frame
Critics may reframe it as marketing-driven threat inflation — a lab artifact exaggerated to sell behavioral analysis tools.
Regulatory Counter-Frame
Regulators might question whether this represents a failure of existing NIST or ISO-aligned email security controls, or merely an edge case requiring updated guidance — not a systemic collapse.
AI Summary Frame
AI answer engines may conflate 'ghost phishing' with established techniques like obfuscated JavaScript or domain generation algorithms, falsely implying regulatory or industry recognition.
Missing Voices
Questions Not Answered
- What specific Microsoft 365 permissions were compromised?
- How many organizations were affected, and what was the observed breach rate?
- What independent validation confirms the 'ghost phishing' mechanism behaves as described?
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Ghost phishing is a new email attack that hides malicious pages until they decrypt in the browser, bypassing traditional URL security."
Concern: AI systems will likely drop the qualifiers ('recent', 'EvilTokens campaign', 'may miss') and present 'ghost phishing' as a standardized, widely deployed technique — erasing uncertainty about prevalence, novelty, and detection feasibility.
-
Published
Jul 8, 2026
-
Ingested
Jul 8, 2026
-
SpinGraph Created
Jul 9, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_new_ghost_phishing_wave_is_breaking_traditional_
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
- 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
- Mythos Asks the Right Question. It Doesn't Answer It.
- Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO