A new phishing campaign, known as “Ghost Phishing” is bypassing traditional email security by hiding malicious content inside encrypted web pages that only decrypt inside the victim's browser. Unlike standard phishing, this method uses legitimate Microsoft Device Code flows to trick users into authorizing access for attackers, rendering passwords and Multi-Factor Authentication (MFA) useless. This campaign is mainly targeting businesses in sectors like consulting, financial services and manufacturing to conduct financial fraud and steal intellectual property.