The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions
ID: a62c32c3-a1da-511c-a510-2fde5b09a2e4
STIX ID: report--a62c32c3-a1da-511c-a510-2fde5b09a2e4
Feed Name: Infoblox Blog
This report documents an active adversary‑in‑the‑middle (AiTM) phishing campaign targeting universities, enterprises, and international institutions (including EU and UN agencies) that leverages compromised, aged domains and multiple AiTM kits (EvilProxy, FlowerStorm/Storm‑1167, Kali365) to proxy legitimate authentication flows, capture session tokens and MFA responses, and establish authenticated sessions; the report describes the phishing lures, impersonated download/auth portals, RDGA/domain patterns, and provides a set of indicators and detection guidance emphasizing DNS/RDGA analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
