Encrypted Phishing Hides Until Microsoft Login Loads

The break is that scanners never get the page defenders think they are checking. The lure stays encrypted until it opens in the victim’s browser, so email and URL inspection can see harmless-looking content and miss the real Microsoft login flow that captures account authorization. EvilTokens is using AES-GCM-encrypted HTML with Microsoft Device Code Phishing to reach Microsoft 365 account takeover without stealing a password. The campaign has hit businesses in the US and Europe, and the blind spot is the rendered page in the browser, not the message that delivered it. That shifts containment from the email body to the login session the user already approved. Once access is granted, the risk extends into mail, files, and cloud services even if the original link was blocked later.

Part of the PlainSec briefing for 2026-07-09

Editions

Sources