BS Summary: This article contains 23 faulty reasoning types, including Appeal to Authority, False Dilemma, and Loss Aversion, with Attempt to Sell a Product or Service as the most egregious example at 24% saturation with 213 hits. Analysis detected 1,415 faulty-reasoning hits from 889 analyzed words, generating a BS Score of 67% and a BS Rank of 75% (5,515 of 21,887 articles). This article is worse (more manipulative) than 74.80% of the article peer group.

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. 
This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. 
For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time are already at stake. 
The Email Looks Safe. 
The Browser Tells a Different Story 
A recent EvilTokens attack shows how a phishing link can appear harmless during initial inspection while still leading to Microsoft 365 account takeover. 
The kit uses Microsoft Device Code Phishing to convince victims to complete a legitimate Microsoft login flow and unknowingly authorize access to their accounts. 
It does not need to steal the password directly. 
The real attack remains hidden until the page opens in the browser. 
Its HTML is encrypted with AES-GCM and becomes visible only after the browser decrypts it and renders the phishing content in the DOM. 
As a result, static URL checks and network-level controls may capture the initial response without seeing what the employee actually sees. 
This visibility gap can lead to: 
* **Longer exposure** to the Microsoft 365 account takeover 
* **Delayed containment** and response decisions 
* **Unauthorized access** to corporate email, files, and cloud services 
* More uncertain **alerts escalated** to senior analysts 
* Higher investigation **workload and operational costs** 
* **Incomplete evidence** for blocking related infrastructure 
The complete attack flow, however, was uncovered inside ANY.RUN's Interactive Sandbox. 
Explore the analysis session to see what the browser revealed and how teams can use this evidence to respond faster. 
Check recent EvilTokens attack and get relevant IOCs 
Where Ghost Phishing Is Hitting Hardest 
ANY.RUN's Threat Intelligence shows recent EvilTokens activity concentrated across the US and Europe, targeting technology, manufacturing, education, banking, consulting, financial services, and managed security providers. 
The overlap is hard to ignore. 
Based on ANY.RUN's sandbox submissions data from 15,000 organizations, phishing exposure in 2026 reached **75.6% in consulting, 72.8% in financial services, 71.9% in manufacturing, 66.7% in banking, and 66.1% among MSSPs**. 
This makes hidden phishing especially dangerous for these sectors. 
One compromised Microsoft 365 account can expose sensitive data, enable business email compromise and fraud, and trigger costly incident response. 
The longer the attack stays hidden, the greater the chance that one account becomes a wider business incident. 
Stop hidden phishing before it costs your business. 
Reduce exposure, incident costs, and account takeover risk. 
Close Visibility Gap 
Make the Ghost Visible Before the Business Pays the Price 
The most effective way to expose ghost phishing is to open suspicious links in a sandbox that supports in-browser data inspection. 
Inside ANY.RUN's Interactive Sandbox, analysts move beyond the encrypted AES-GCM response and see what happens after the page decrypts. 
They can watch the phishing content appear in the DOM, connect the change to a Fetch/XHR request, and trace the Microsoft device code back to the /api/device/start endpoint. 
The decrypted HTML DOM viewed in the in-browser data investigation panel 
The in-browser data view brings the full attack flow into one investigation: 
* DOM snapshots show when the hidden page changes and the user code appears. 
* HTTP requests reveal the backend communication behind the device-code flow. 
* URL details expose the final destination and triggered detection signatures. 
* Indicators provide domains, endpoints, hashes, and infrastructure for further hunting. 
Instead of reconstructing the attack manually, teams get direct evidence of how the page behaves, what it requests, and which artifacts support containment and detection. 
From Browser-Level Evidence to a Clearer SOC Handoff 
To carry this evidence from Tier 1 to Tier 2, the investigation automatically generates a report with an AI summary and recommended next steps. 
Auto-generated report from EvilTokens analysis session 
Instead of rebuilding the case from raw browser data, senior analysts receive the key findings, observed behavior, indicators, and response context in one place. 
This makes handoffs faster, reduces repeated work, and helps teams move from validation to containment with less delay. 
Stop Ghost Phishing in the Browser Before It Reaches the Business 
The EvilTokens case exposes an uncomfortable truth: an email can pass inspection while the real attack waits inside the browser. 
Without browser-level visibility, the SOC is forced to make high-stakes decisions with partial evidence. 
That delay gives attackers more time to gain access, expand their reach, and turn one compromised Microsoft 365 account into a costly business incident. 
This helps security leaders: 
* **Shrink the exposure window** before a compromised account becomes a wider incident 
* **Reduce pressure on senior analysts** by giving Tier 1 enough evidence to resolve more cases 
* **Accelerate containment** with complete attack context available from the first escalation 
* **Improve detection coverage** using browser behavior, infrastructure, and repeatable attack patterns 
* **Lower the cost of phishing response** by cutting manual investigation and duplicated work 
* **Make risk decisions with evidence** instead of relying on clean scans or inconclusive verdicts 
Modern phishing no longer reveals itself fully in the email or initial URL response. 
Security teams need visibility that follows the attack into the browser and exposes it before the business pays the price. 
**Reduce business exposure**: Give analysts full browser evidence to contain ghost phishing faster and stop one compromised account from escalating into a costly incident. 
Article reasoning-pattern comparisonThis article: 0.0%The Hacker News: 1.8%The Hacker News: 1.9%Confirmation Bias0.0%This article: 0.0%The Hacker News: 0.8%The Hacker News: 1.2%Anchoring Bias0.0%This article: 3.1%The Hacker News: 3.5%The Hacker News: 3.3%Availability Heuristic3.1%This article: 1.3%The Hacker News: 1.5%The Hacker News: 1.5%Representativeness Heuristic1.3%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.6%Hindsight Bias0.0%This article: 11.9%The Hacker News: 2.7%The Hacker News: 2.5%Overconfidence Bias11.9%This article: 4.4%The Hacker News: 2.8%The Hacker News: 2.7%Framing Effect4.4%This article: 12.6%The Hacker News: 1.3%The Hacker News: 1.0%Loss Aversion12.6%This article: 0.0%The Hacker News: 0.6%The Hacker News: 0.6%Status Quo Bias0.0%This article: 1.6%The Hacker News: 0.1%The Hacker News: 0.1%Sunk Cost Effect1.6%This article: 6.2%The Hacker News: 1.4%The Hacker News: 1.3%Optimism Bias6.2%This article: 7.8%The Hacker News: 1.4%The Hacker News: 1.6%Pessimism Bias7.8%This article: 10.1%The Hacker News: 6.6%The Hacker News: 6.7%Negativity Bias10.1%This article: 0.0%The Hacker News: 1.5%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 1.3%The Hacker News: 0.8%The Hacker News: 0.6%Halo Effect1.3%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 8.4%The Hacker News: 1.0%The Hacker News: 1.5%Recency Bias8.4%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.3%Primacy Effect0.0%This article: 3.0%The Hacker News: 0.1%The Hacker News: 0.1%Blind-Spot Bias3.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Straw Man0.0%This article: 15.1%The Hacker News: 3.7%The Hacker News: 4.0%Appeal to Authority15.1%This article: 13.6%The Hacker News: 2.4%The Hacker News: 1.6%False Dilemma13.6%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 4.9%The Hacker News: 5.1%The Hacker News: 4.3%Hasty Generalization4.9%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.2%Bandwagon0.0%This article: 0.7%The Hacker News: 1.3%The Hacker News: 1.1%Appeal to Emotion0.7%This article: 0.0%The Hacker News: 0.9%The Hacker News: 0.5%Begging the Question0.0%This article: 7.0%The Hacker News: 1.8%The Hacker News: 1.9%Post Hoc (False Cause)7.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%The Hacker News: 0.4%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%The Hacker News: 0.2%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%The Hacker News: 0.5%The Hacker News: 0.3%Composition/Division0.0%This article: 4.8%The Hacker News: 1.2%The Hacker News: 1.0%Anecdotal4.8%This article: 2.8%The Hacker News: 0.1%The Hacker News: 0.1%No True Scotsman2.8%This article: 2.7%The Hacker News: 1.3%The Hacker News: 2.3%Ambiguity (Equivocation)2.7%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%The Hacker News: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 0.0%The Hacker News: 0.8%The Hacker News: 1.4%Unattributed Quote0.0%This article: 0.0%The Hacker News: 0.3%The Hacker News: 0.9%Quote-first Misdirection0.0%This article: 2.2%The Hacker News: 1.9%The Hacker News: 2.3%Biased Writer Voice2.2%This article: 9.4%The Hacker News: 5.0%The Hacker News: 4.4%Indoctrination9.4%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%The Hacker News: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 24.0%The Hacker News: 6.7%The Hacker News: 3.0%Attempt to Sell a Product or S…24.0%

889 words analyzed.

Speakers

1speaker9.7%attributed speech803writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 9 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageANY.RUN • 11 words • 100.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageANY.RUN • 25 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageANY.RUN • 31 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 8 words • 100.0% coverageWriter's voice • 3 words • 100.0% coverageWriter's voice • 10 words • 100.0% coverageWriter's voice • 21 words • 100.0% coverageANY.RUN • 19 words • 100.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 6 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverageWriter's voice • 18 words • 100.0% coverageWriter's voice • 11 words • 100.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 20 words • 100.0% coverageWriter's voice • 24 words • 100.0% coverage
Selected voice

ANY.RUN

100%flagged-word coverage
86 attributed words100% of attributed speech86% writer coverage
0%17.5%35.0%Attempt to Sell a Product +12.1 ptsWriter: 22.8%ANY.RUN: 34.9%34.9%Indoctrination-10.5 ptsWriter: 10.5%ANY.RUN: 0.0%0.0%Biased Writer Voice-2.5 ptsWriter: 2.5%ANY.RUN: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.