EvilTokens: how ghost code threatens companies in the US and Europe

EvilTokens hides its malicious payload through browser-side encryption. Discover how to detect it and protect your organization.

martes, 7 de julio de 2026 • 2 min read • Q2BSTUDIO Team

Encrypted code that hides Microsoft 365 account theft

Enterprise cybersecurity faces a new generation of threats that exploit the complexity of the digital ecosystem. One of the most concerning is EvilTokens, a phishing kit that uses ghost code —hidden behind AES-GCM encryption and decrypted only in the browser— to evade static URL analysis. This creates a blind spot in Security Operations Centers (SOCs), which may overlook the true malicious content until it is too late. The attack leverages the legitimate device login flow of Microsoft, tricking the victim into authorizing access without directly stealing their credentials. As a result, companies in the United States and Europe, especially in sectors such as managed services, technology, manufacturing, education, banking, and consulting, are exposed to an elevated risk of Microsoft 365 account takeover.

Faced with this situation, browser-level visibility becomes essential. Interactive sandbox tools allow capturing the decrypted DOM, HTTP requests, and real-time changes, providing analysts with the necessary evidence to validate the threat and respond quickly. Additionally, Threat Intelligence enables pivoting from an EvilTokens session to other phishing kits and related infrastructures, improving detection and threat hunting.

For organizations looking to strengthen their security posture, having specialized technology partners makes a difference. At Q2BSTUDIO, we understand that cybersecurity is not an isolated product, but a continuous process that must be integrated with the rest of the digital infrastructure. That is why we offer comprehensive cybersecurity and pentesting services, designed to identify vulnerabilities in applications, networks, and processes. Additionally, we combine this expertise with custom application development and custom software that incorporate security from the design phase, ensuring that every line of code is free from the weaknesses exploited by threats like EvilTokens.

The fight against ghost code also requires a robust and scalable infrastructure. Our AWS and Azure cloud services enable the deployment of secure and elastic environments, where continuous monitoring and custom detection rules can run seamlessly. At the same time, artificial intelligence and AI agents are transforming companies' ability to anticipate attacks: from behavior-based early warning systems to enterprise AI platforms that automate incident response. Even in the realm of decision-making, business intelligence through tools like Power BI helps visualize threat patterns and optimize resource allocation in security teams.

Ultimately, EvilTokens reminds us that modern security goes beyond superficial URL analysis. It demands a deep understanding of browser behavior, strategic integration of technology services, and a preventive approach that only multidisciplinary teams can provide. At Q2BSTUDIO, we work to ensure that Spanish and Latin American companies (and their counterparts in the US and Europe) not only defend themselves better, but also transform cybersecurity into a sustainable competitive advantage.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.