INTEL_REPORT
The Hacker News · published 7/8/2026, 1:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
New Ghost Phishing Wave Is Breaking Traditional Email Security A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time New Ghost Phishing W…
https://thehackernews.com/2026/07/new-ghost-phishing-wave-is-breaking.html
sha256:78ae85eabf5b59d55f940881efc578b99bb4b1b58c9f4b8d46f7188ee1afb159
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.