{
  "Event": {
    "analysis": "1",
    "date": "2026-06-23",
    "extends_uuid": "",
    "info": "[Threat Intel] \"Ghost\" Code Phishing Analysis",
    "protected": false,
    "publish_timestamp": "1782525124",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1782525124",
    "uuid": "d15a3a8a-c31d-41dc-8f21-e33c946946a6",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#60f452",
        "local": false,
        "name": "misp-galaxy:producer=\"ANY.RUN\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#ed66f6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Steal Web Session Cookie - T1539\"",
        "relationship_type": ""
      },
      {
        "colour": "#77a4ec",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Email Collection - T1114\"",
        "relationship_type": ""
      },
      {
        "colour": "#c202a1",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1566.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#ff841f",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Layer Protocol - T1071\"",
        "relationship_type": ""
      },
      {
        "colour": "#a92e1c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Deobfuscate/Decode Files or Information - T1140\"",
        "relationship_type": ""
      },
      {
        "colour": "#bce57a",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Web Service - T1567\"",
        "relationship_type": ""
      },
      {
        "colour": "#b25e1b",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Use Alternate Authentication Material - T1550\"",
        "relationship_type": ""
      },
      {
        "colour": "#62e1b7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Browser Session Hijacking - T1185\"",
        "relationship_type": ""
      },
      {
        "colour": "#9e0269",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Service - T1102\"",
        "relationship_type": ""
      },
      {
        "colour": "#3780c6",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"User Execution - T1204\"",
        "relationship_type": ""
      },
      {
        "colour": "#1b95cd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"",
        "relationship_type": ""
      },
      {
        "colour": "#59699c",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"",
        "relationship_type": ""
      },
      {
        "colour": "#e08bb2",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Obfuscated Files or Information - T1027\"",
        "relationship_type": ""
      },
      {
        "colour": "#23cf0e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Remote Email Collection - T1114.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#0088cc",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration to Cloud Storage - T1567.002\"",
        "relationship_type": ""
      },
      {
        "colour": "#fdd85e",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Access Token Manipulation - T1134\"",
        "relationship_type": ""
      },
      {
        "colour": "#92e858",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Web Protocols - T1071.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#5884a7",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Malicious Link - T1204.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#5300bd",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Application Access Token - T1550.001\"",
        "relationship_type": ""
      },
      {
        "colour": "#37c019",
        "local": false,
        "name": "misp-galaxy:mitre-attack-pattern=\"Cloud Accounts - T1078.004\"",
        "relationship_type": ""
      },
      {
        "colour": "#b8ab01",
        "local": false,
        "name": "misp-galaxy:target-information=\"United States\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#10003f",
        "local": false,
        "name": "rectifyq:sub-category=\"tool-profile\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356439",
        "to_ids": false,
        "type": "link",
        "uuid": "c456a5e8-82f7-4424-912f-d8b2b7bc4549",
        "value": "https://any.run/cybersecurity-blog/eviltokens-ghost-code-analysis/"
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356439",
        "to_ids": false,
        "type": "text",
        "uuid": "5f17ccea-f8e1-4ebb-9807-1c0f583b0039",
        "value": "EvilTokens is a sophisticated phishing kit that conceals critical components of its attack through browser-side AES-GCM encryption, creating visibility gaps for traditional static URL analysis. The kit exploits Microsoft's legitimate device login flow through OAuth device-code phishing to gain account access without directly stealing passwords. Targeting organizations primarily in the United States and Europe, EvilTokens focuses on managed security services, technology, manufacturing, education, banking, and consulting sectors. The encrypted landing page only reveals its malicious content after browser decryption, requiring dynamic analysis to uncover the complete attack chain. The kit uses multiple stages including gate checks, user code requests, and session monitoring to complete Microsoft 365 account takeovers while appearing legitimate through final redirects to OneDrive."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782356439",
        "to_ids": false,
        "type": "text",
        "uuid": "657075d9-f196-469e-9db9-37cef519248d",
        "value": "Name: \"Ghost\" Code Phishing Analysis\nAuthor: AlienVault\nAdversary: \nTags: [\"oauth device-code phishing\", \"dom manipulation\", \"microsoft 365 compromise\", \"phishing kit\", \"browser-based attack\", \"aes-gcm encryption\", \"eviltokens\"]\nTgtd countries: [\"United States of America\"]\nMlwr families: [\"EvilTokens\"]\nAttack_ids: [\"T1539\", \"T1114\", \"T1566.002\", \"T1071\", \"T1140\", \"T1567\", \"T1550\", \"T1185\", \"T1102\", \"T1204\", \"T1566\", \"T1078\", \"T1027\", \"T1114.002\", \"T1567.002\", \"T1134\", \"T1071.001\", \"T1204.001\", \"T1550.001\", \"T1078.004\"]\nIndustries: [\"Technology\", \"Manufacturing\", \"Education\", \"Finance\", \"Government\"]"
      },
      {
        "category": "Payload delivery",
        "comment": "No sample in VT\r\nLast check:26/06/2026",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782467490",
        "to_ids": true,
        "type": "md5",
        "uuid": "697b339c-89ac-4a18-9dd4-c97196331b25",
        "value": "fcd1b654a0b3e8f85ca7cfdafe494d4b",
        "Tag": [
          {
            "colour": "#260091",
            "local": false,
            "name": "rectifyq:ioc=\"enriched\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"VirusTotal\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
            "relationship_type": ""
          },
          {
            "colour": "#626567",
            "local": false,
            "name": "rectifyq:no-samples-in=\"Tria.ge\"",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}