logo

The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions

ID: a62c32c3-a1da-511c-a510-2fde5b09a2e4

STIX ID: report--a62c32c3-a1da-511c-a510-2fde5b09a2e4

Feed Name: Infoblox Blog

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

Author: Infoblox Threat Intel

...
...

This report documents an active adversary‑in‑the‑middle (AiTM) phishing campaign targeting universities, enterprises, and international institutions (including EU and UN agencies) that leverages compromised, aged domains and multiple AiTM kits (EvilProxy, FlowerStorm/Storm‑1167, Kali365) to proxy legitimate authentication flows, capture session tokens and MFA responses, and establish authenticated sessions; the report describes the phishing lures, impersonated download/auth portals, RDGA/domain patterns, and provides a set of indicators and detection guidance emphasizing DNS/RDGA analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.