EvilTokens: Ghost code threatens US and European companies

EvilTokens hides its malicious code after browser decryption. Discover how SOC can detect this threat and protect Microsoft 365 accounts.

martes, 7 de julio de 2026 • 3 min read • Q2BSTUDIO Team

EvilTokens: Invisible threat for US and European companies

In the current cybersecurity landscape, threats constantly evolve to bypass traditional defenses. One of the most sophisticated and dangerous to have emerged in recent months is EvilTokens, a phishing kit that uses ghost code to hide its true nature until it is executed in the victim's browser. This type of attack represents a significant challenge for security teams, as static URL analysis tools often overlook the most critical part of the deception, leaving organizations exposed to account takeover risks in Microsoft 365. The technique used by EvilTokens abuses the legitimate Microsoft device login flow, convincing the user to authorize access without directly stealing their credentials. This makes the attack particularly difficult to detect and stop in time.

For companies operating in the United States and Europe, regions where this kit's activity is most concentrated, the lack of visibility into the actual behavior of pages after execution in the browser can result in slower response times, unnecessary escalations, and prolonged exposure to corporate account takeover. The most affected sectors include managed security services, technology, manufacturing, education, banking, and financial consulting. In all of them, access to a single Microsoft 365 account can compromise sensitive data, internal communications, and connected business services. Cybersecurity must be addressed from multiple layers, and one of the most effective is browser-level inspection, which allows revealing decrypted content and dynamic interactions that attackers try to hide.

From a technical perspective, EvilTokens uses AES-GCM encryption on the landing page, so that the malicious HTML only becomes visible after client-side decryption. Security analysts need tools that can capture these changes in the DOM, HTTP requests, and behavioral patterns to reconstruct the attack chain. This is where the integration of artificial intelligence and AWS and Azure cloud services can enhance detection and response capabilities. Modern interactive sandboxing platforms allow SOC teams to observe in real time how ghost code is deployed, identify the endpoints used to obtain the user code, and track the OAuth session status. This visibility is crucial to reduce manual workload and accelerate containment decisions.

At Q2BSTUDIO, as a software and technology development company, we understand that protection against threats like EvilTokens cannot rely solely on static tools. That is why we offer specialized cybersecurity services that include penetration testing, vulnerability analysis, and secure architecture design. Additionally, our experience in custom applications and custom software allows us to develop solutions tailored to the specific needs of each organization, incorporating security controls from the design phase. The combination of business intelligence services with Power BI can also help visualize attack patterns and correlate security events, while AI agents and enterprise AI optimize real-time anomaly detection. Likewise, our ability to implement secure cross-platform platforms ensures that corporate applications withstand advanced phishing attempts.

The EvilTokens threat underscores the need to evolve security strategies towards a more dynamic and proactive approach. Companies that still rely exclusively on URL analysis or static signatures risk being blind to attacks that only deploy after execution in the browser. Investing in browser-level inspection capabilities, continuous staff training, and advanced technological solutions is the best defense against ghost code. At Q2BSTUDIO, we accompany organizations on this path, providing tools and knowledge so that their security teams can validate threats quickly and accurately, reducing exposure time and strengthening the overall cybersecurity posture.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.