Breaking Down the Misconfigured Server: Uncovering Phishing Operations Targeting Microsoft 365 (2026)

In the world of cybersecurity, the battle against phishing attacks is an ongoing and ever-evolving challenge. A recent discovery by French security firm Lexfo has shed light on a sophisticated operation involving a misconfigured server, revealing a series of Evilginx phishing campaigns targeting Microsoft 365 users. This incident highlights the importance of staying vigilant and implementing robust security measures to protect against such threats.

The story begins with a simple yet crucial detail: a misconfigured server left a Python web server running on a public port with directory listing enabled. This oversight, seemingly minor, exposed a wealth of sensitive information, including phishing configurations, credential-harvesting logs, and even the operator's Telegram session files. It was this exposure that led Lexfo to uncover a much larger operation.

The operator, codemado, an Egyptian actor active in VoIP and hacking forums since 2018, was found to be running a Microsoft 365 AiTM platform. The campaign, which went live on April 20, targeted corporate mailboxes and utilized a custom fork of the open-source Evilginx proxy, cloned from public GitHub. What's more intriguing is that codemado did not build the framework himself; he cloned it and compared different kits side by side.

One of the kits, red-queen, was developed by a Nigerian operator known as mail-argenta. This fork demonstrates a high level of polish, with modifications to defeat Subresource Integrity checks and a URL-rewriting engine to evade path-based detection. It also pre-fills the victim's email address to reduce abandonment and sets a one-year TTL on captured Microsoft session cookies, allowing for extended use even after password resets.

The third fork, black-queen, stands out for its quiet and stealthy approach. Its author, saroula01, built it around Microsoft's OAuth device code flow, a legitimate sign-in path for input-constrained devices. This technique, while not a bypass, leverages the genuine Microsoft infrastructure to satisfy the MFA prompt, making it challenging to detect.

The report highlights the use of AI-assisted development across all three operations, with varying degrees of involvement. saroula01's version, in particular, shows signs of AI influence, with two git commits co-authored by Claude models. mail-argenta's instructions.txt file is a verbatim save of an AI coding session, showcasing the URL-rewriting feature's development.

The implications of these findings are significant. The barrier to launching a successful phishing campaign has seemingly dropped to near zero, with operators utilizing public repositories, kits that can be purchased for a few hundred dollars, and AI assistance to create custom tools. This trend raises concerns about the increasing sophistication and accessibility of phishing attacks.

To defend against these threats, Lexfo recommends implementing phishing-resistant MFA, FIDO2, or passkeys, which can shut down the Evilginx side of the attack by binding the sign-in to the real domain. Additionally, Conditional Access policies play a crucial role in blocking device-code abuse by reevaluating stolen tokens from outside allowed ranges. Continuous Access Evaluation and IP-based location policies further enhance security.

In conclusion, this incident serves as a stark reminder of the evolving nature of cybersecurity threats. As attackers become more sophisticated and resourceful, it is imperative for organizations to stay proactive and implement robust security measures. By staying informed and adopting a multi-layered defense strategy, we can collectively combat the ever-present challenge of phishing attacks and safeguard our digital assets.

Breaking Down the Misconfigured Server: Uncovering Phishing Operations Targeting Microsoft 365 (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Carmelo Roob

Last Updated:

Views: 6514

Rating: 4.4 / 5 (65 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Carmelo Roob

Birthday: 1995-01-09

Address: Apt. 915 481 Sipes Cliff, New Gonzalobury, CO 80176

Phone: +6773780339780

Job: Sales Executive

Hobby: Gaming, Jogging, Rugby, Video gaming, Handball, Ice skating, Web surfing

Introduction: My name is Carmelo Roob, I am a modern, handsome, delightful, comfortable, attractive, vast, good person who loves writing and wants to share my knowledge and understanding with you.