惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
S
Security Affairs
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone
Latest news
Latest news
Simon Willison's Weblog
Simon Willison's Weblog
NISL@THU
NISL@THU
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 司徒正美
博客园_首页
人人都是产品经理
人人都是产品经理
Project Zero
Project Zero
S
Schneier on Security
Recorded Future
Recorded Future
N
News and Events Feed by Topic
T
The Exploit Database - CXSecurity.com
博客园 - 【当耐特】
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
V2EX - 技术
V2EX - 技术
Hacker News: Ask HN
Hacker News: Ask HN
酷 壳 – CoolShell
酷 壳 – CoolShell
有赞技术团队
有赞技术团队
G
GRAHAM CLULEY
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Engineering at Meta
Engineering at Meta
M
MIT News - Artificial intelligence
The Last Watchdog
The Last Watchdog
B
Blog
V
Visual Studio Blog
MongoDB | Blog
MongoDB | Blog
量子位
A
Arctic Wolf
Cloudbric
Cloudbric
I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
C
Cybersecurity and Infrastructure Security Agency CISA
爱范儿
爱范儿
Recent Announcements
Recent Announcements
GbyAI
GbyAI
P
Palo Alto Networks Blog
D
DataBreaches.Net
H
Help Net Security
AI
AI
博客园 - 叶小钗

Infoblox Blog

FedRAMP DDI Management with Infoblox Government Cloud The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play NIST Maps DNS Security to the Cybersecurity Framework 2.0 Trusted Infrastructure Data for AI and AgenticOps | Infoblox Meet Your Security Analyst’s New AI Teammate | Infoblox IQ DCloud Uni-App: One Framework, 236,000+ Scam Sites Operation Endgame VS SocGholish Fake Updates Human Judgment Hacks: How Lookalike Domains Work Residential Proxies in the Wild Unlocking Universal DDI on Equinix: Infoblox Brings Cloud-First DDI to Equinix Network Edge “Headless”? What Is It and Do I Need to Go There? The Alert Is Already Too Late The Half of Your Attack Surface Nobody Owns Infoblox Earns Terraform Partner Premier Status for NIOS Provider What 550 Security Leaders Just Told Us about the Age of AI, and Why Preemptive Digital Risk Protection Can’t Wait Lookalike Domains Expose the iPhone Theft Economy Amusing Numerology: Analysis of the Numbers in Domain Names 4 Trends Shaping the Future of Network Operations Preemptive Threat Disruption at Scale: How Infoblox and Axur Turn External Risk into Protection Why the Axur Acquisition Marks a Turning Point for Preemptive Security Don’t Wait To Be Attacked: Stop Phishing, C2 and Data Exfiltration with Infoblox Threat Intelligence in AWS Network Firewall Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs AI, Project Glasswing and DNS: Beyond Vulnerabilities Three Infoblox Integrations with Google Cloud That Give Enterprise Teams More Control Over Their Networks Protective DNS: Why Telcos Are Turning to DNS as the Platform for Consumer Security Automating Infoblox DDI with Red Hat Ansible | Configuration as Code for DNS, DHCP and IPAM Hiding in Plain Sight: Abusing Composite Domain Names What You Cannot See is Hurting You Most NIST SP 800-81r3: A Long-Overdue Wake-Up Call for DNS Security Patterns, Pirates, and Provider Action: What We Learned Working with Keitaro NIST SP 800-81r3: What’s New? No Reach, No Risk: The Keitaro Abuse in Modern Cybercrime Distribution Unified Asset Visibility: A Strategic Imperative for CIOs and CISOs Infoblox Partners with Leading SASE Vendors to Modernize DNS and DHCP for Distributed Enterprises NIST DNS Security Best Practices: Top 5 Takeaways Break out the bubbly: NIST SP 800-81r3 has been published! Empowering Women to Lead in APJ: Infoblox at the Leadership Summit for Women in Technology, AI & Cyber
Inside a Global Procurement-Themed AiTM Phishing Campaign
Infoblox Threat Intel · 2026-07-22 · via Infoblox Blog

Authors: Darby Wise, Nick Sundvall

Executive Summary

Right now, someone may be sitting invisibly between your users and their login pages. They’re not guessing passwords. They’re not cracking MFA codes. They’re simply waiting, and when the authentication succeeds, they take the session. This is adversary-in-the-middle phishing (AiTM), and it has quietly become one of the most effective techniques in the modern threat actor’s toolkit. The campaign we will detail here targets universities, enterprises, and multinational institutions, including European Union and United Nations agencies. The actor routes attacks through seemingly compromised small-business sites and turns trusted infrastructure into cover. The goal is no longer access: it’s authenticated trust.

In May 2026, a contact shared an email they received related to a security event they were working to understand. What started as a phishing email to a small group of employees had snowballed. Once those accounts were compromised, the actor used them to distribute their lures more broadly across the organization. Using the email they shared with us, we were able to uncover a sophisticated AiTM phishing campaign targeting dozens of organizations with project-themed lures. 

This is not an isolated trend. Last December, we documented a separate AiTM actor targeting U.S. university SSO portals using Evilginx. Where that actor relied on freshly registered phishing domains, this one uses aged, often dormant domains that are likely compromised and injected with a PHP file to host fake file download sites.

By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time, allowing them to bypass many of the controls organizations rely on to secure their identities. The takeaway: stronger authentication alone isn’t enough when attackers can hijack the session itself.

The campaigns described in this blog appear to be the work of a single actor who leverages multiple AiTM phishing kits, including Evilginx, FlowerStorm, and Kali365, to harvest user credentials. The use of procurement lures and emails sent from previously compromised accounts indicates that they are targeting businesses rather than individuals. The attack chain includes brand impersonation of well-known contract platforms and perfectly replicated login portals for the targets. The goal is to collect credentials for high value networks rather than grandpa’s credit card.

Campaign Analysis

Phishing Emails

This campaign begins with emails sent from compromised organizational accounts, a tactic used to lend credibility to the lures. The emails themselves are themed around professional workflows: requests for information (RFIs), formal bid invitations, and shared project documentation. Examples of select phishing lures are shown below in Figure 1. These emails also feature common social engineering elements, including fake deadlines that pressure recipients to act quickly, and confidentiality language that discourages them from sharing the email or seeking a second opinion.

Figure 1a
Figure 2b

Figure 1. Redacted screenshot of sample phishing emails sent to targeted victims through compromised Microsoft Outlook accounts

We don’t have information about how the accounts of the small group of initial recipients were initially compromised, but it is common for threat actors to rapidly weaponize such accounts to distribute identical lures to internal and external contacts as they did in this case. They transformed trusted mailboxes into force multipliers for further compromise. The combination of legitimate infrastructure abuse, institutional brand impersonation, and social engineering reflects a mature and scalable operation designed to undermine trust.

Impersonated Login Portals

Once victims click on the link in the phishing email, they are sent through a carefully engineered sequence of fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating trusted services including Microsoft, OpenGov, and European financial institutions. The spoofed portals and pages aim to build user trust while obscuring the underlying phishing infrastructure. Rather than directing victims immediately to a credential harvesting page, the actor introduces several intermediate steps that mimic legitimate download workflows and verification processes.

Victims who click the links embedded in the phishing emails are first directed to the websites hosting the fake document download pages as seen in Figure 2 below. In many cases, the victim’s email address is embedded directly in the URL path (e.g., /user@company[.]com/), reinforcing the illusion that the content is intended specifically for them.

Figure 2

Figure 2. Screenshot of a fake download page impersonating ConstructConnect

When the victim attempts to download the files, the page presents a prompt requiring their email address to continue. To enhance legitimacy, these prompts feature branding for popular government and construction operations platforms such as OpenGov and ConstructConnect. Once the victim enters a valid email, they are redirected to either a legitimate Cloudflare Turnstile or a generic CAPTCHA instance hosted on actor-controlled domains. These domains are likely generated by a registered domain generation algorithm (RDGA); the domains associated with EvilProxy and FlowerStorm/Storm-1167 phishing kits follow the RDGA patterns in Table 1. Phishing pages using the FlowerStorm kit are hosted on subdomains of the RDGA domains; some subdomains are random English words or strings, while others follow company branding themes (e.g. ajgroupuae[.]usersatisfactionlab[.]de).

In some cases, the actor-controlled phishing page is conditionally cloaked: users who provide non-targeted email addresses during the prompt step may be redirected to a benign decoy page. In one test, we were redirected to the legitimate page for Houzz, a home design and renovation platform, after entering a fake email address in a prompt that was impersonating ConstructConnect.

Phishing Kit RDGA Pattern Sample Domains
FlowerStorm/Storm-1167 <two to four corporate buzzwords>.de usersatisfactionlab[.]de
sustainablegrowthlaunch[.]de
solidhostingservices[.]de
reliablecontinuitysolutions[.]de
innovativegrowthstrategy[.]de
designenhancessatisfaction[.]de
EvilProxy <two to four corporate buzzwords>.<net or com> q1evaluationperformance[.]net
corporatetermscompliance[.]com
assessmentevaluationreport[.]com

Table 1. RDGA domain patterns for phishing pages

Once the victim completes the CAPTCHA, they are directed to a fake Microsoft authentication page; some of these pages also feature branding elements associated with the targeted organization. Figure 3 shows an example of a page impersonating the European Investment Bank.

Figure 3

Figure 3. Redacted screenshot of a fake authentication page impersonating the European Investment Bank

Beware the Invisible Actor

These login pages aren’t just forms in a simple phishing campaign: they are components of an AiTM phishing framework. The actor rotates between multiple AiTM kits—including EvilProxy and FlowerStorm/Storm-1167—to intercept MFA-protected sessions in real time and maintain operational resilience. When a user enters their credentials and completes MFA, the information is relayed in real time to the legitimate authentication service, while session tokens and cookies are intercepted by the attacker. This allows the operator to establish authenticated sessions without needing to directly bypass MFA protections.

All stages of this campaign mirror legitimate download and authentication workflows to build user trust. By taking the victims through several seemingly legitimate interactions (file access, email verification, CAPTCHA completion, login) the actor reduces the likelihood that any single step will trigger suspicion or detection.

Phishing Kits

Analysis of the campaign infrastructure indicates that the actor rotates between multiple AiTM phishing-as-a-service (PhaaS) platforms rather than relying on a single phishing framework. Table 2 shows information about the kits we’ve observed the threat actor using as part of this campaign, although they’ve likely used other kits as well.

Kit First Seen Core Technique Target Victims Threat Actor Usage
EvilProxy 2022 Reverse proxy Credentials for a variety of services across many sectors Broad PhaaS use; enables low-skill actors
FlowerStorm June 2024 Reverse proxy Microsoft 365 credentials mainly in professional services, finance, legal, manufacturing sectors Likely a rebrand of Rockstar2FA after its disruption in 2024
Kali365 April 2026 Device code abuse + AiTM session capture Microsoft 365 credentials across many sectors Tiered reseller and affiliate model; low technical barrier

Table 2. AiTM phishing kits observed in this campaign

Fake Document Download Sites

Several phishing emails we were able to analyze contained a link to testserveren[.]com, a domain hosting a page designed to mimic a legitimate file-sharing platform, as shown in Figure 4, which presents the victim with what appears to be four shared files available for download; filenames are carefully chosen to match those referenced in the original lure email. Downloading these files will redirect the victim to a phishing site rather than delivering the content they expect.

Figure 4

Figure 4. Fake UN file download page

A different URL on testserveren[.]com hosted a similar page impersonating OpenGov, a procurement and contract management company used by state and local governments in the United States. See Figure 5.

Figure 5

Figure 5. Email prompt impersonating OpenGov

Notably, testserveren[.]com appears to have sat completely dormant for nearly a decade, with no trace of the site serving anything at all before May 2026. While registration data is private, there are no obvious indicators of a change in ownership around the time the malicious activity began.

It was a similar story for another domain, barifurniture[.]net, which was registered in 2015 and did not show signs of malicious activity until May 2026. The domain name implies that it is a furniture company, and historically the content of the domain pertained to selling furniture. Yet as Figure 6 shows, this fake download page is branded as “NUS Consulting Group.”

Figure 6

Figure 6. Fake NUS Consulting Group file download page

Our investigation identified dozens of additional domains hosting near-identical content, consistent with the use of a shared phishing kit. The domains in this cluster share several characteristics that point toward compromise rather than fresh registration: the average domain age exceeds six years, registration and hosting details vary across the cluster, and the domains appear to have been registered at seemingly unrelated times. On top of that, the sites appear to inject an index.php file that loads the malicious content. Taken together, these traits suggest the actor may have compromised aged domains to lend credibility to the campaign and evade detection.

Security Implications and Conclusion

Our research into this AiTM phishing actor reflects a broader evolution in phishing operations. Attackers are no longer focused solely on stealing credentials, but also on stealing trusted, authenticated sessions to gain unauthorized access to user accounts. Phishing campaigns are becoming infrastructure-aware, identity-centric, and increasingly optimized to exploit user trust rather than technical vulnerabilities. By creating a framework out of compromised (aged) legitimate domains, multiple AiTM frameworks, and carefully staged user interactions, the actor behind these attacks demonstrates a mature understanding of modern identity defenses and how to circumvent them.

As AiTM tooling becomes more accessible and legitimate websites continue to be repurposed as attack infrastructure, organizations can no longer view MFA as a standalone defense. When authentication flows are proxied in real time, attackers can capture and reuse session tokens, effectively inheriting the victim’s authenticated identity. As organizations continue to adopt cloud-first architectures and identity-centric security models, the compromise of a trusted, MFA-validated session carries the same risk as a compromised password—without triggering the controls built to catch one. Understanding how modern phishing operations bypass identity protections is becoming essential for defending enterprise environments at scale.

As AiTM tooling matures and compromised legitimate infrastructure increasingly proves to be an effective delivery mechanism, detection approaches that rely solely on domain reputation, URL analysis, or content inspection may prove to be ineffective. What persists is DNS. The domains underpinning these campaigns leave fingerprints: RDGA patterns, subdomain conventions, and infrastructure reuse that remain visible to passive DNS analysis long after individual phishing URLs have expired. DNS-based threat intelligence offers a detection layer that operates upstream of authentication, before the user enters credentials or clicks through a CAPTCHA gate, and before the attacker walks away with a stolen session token.

Indicators

The table below provides a curated selection of indicators related to the threats discussed. A more comprehensive list of indicators can be found in our GitHub repository.

Indicator Description
barifurniture[.]net
satoriestate[.]com
sohantraders[.]com
testserveren[.]com
vresortsliving[.]com
Domains likely compromised and hosting fake document download pages
consistenthostinghub[.]de
designenhancessatisfaction[.]de
evergreenhostingoptions[.]de
innovativegrowthstrategy[.]de
reliablecontinuitysolutions[.]de
sustainablegrowthlaunch[.]de
solidhostingservices[.]de
usersatisfactionlab[.]de
FlowerStorm/Storm-1167 Domains
assessmentevaluationreport[.]com
corporatetermscompliance[.]com
employeehandbookcompliance[.]com
esignidentification[.]com
q1evaluationperformance[.]net
EvilProxy PhaaS Domains
duemineral[.]uk Kali365 PhaaS Domain