GhostFrame and the Failure of HTML-Only Phishing Detection
GhostFrame is a useful wake-up call because it does not just hide phishing behind a new domain or a better lure. It hides the real credential-harvesting experience inside the browser's rendering path, leaving many source-only inspections looking at the wrong thing.