Misconfigured Server Exposes Three Evilginx Phishing Ops Targeting M365
ID: 9b872db8-413f-5767-96c2-f4f79e169395
STIX ID: report--9b872db8-413f-5767-96c2-f4f79e169395
Feed Name: CosmicBytez Labs
Lexfo discovered that an attacker accidentally exposed a public HTTP directory (via 'python3 -m http.server') containing a readable .bash_history, which revealed three active Evilginx-based Microsoft 365 phishing campaigns. The report explains how Evilginx acts as an adversary-in-the-middle to capture session cookies and bypass MFA, outlines the attack flow, lists mitigations (phishing-resistant MFA, conditional access, token protection, domain intelligence, and user training), and highlights OPSEC lessons and the value of scanning exposed infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
