logo

Misconfigured Server Exposes Three Evilginx Phishing Ops Targeting M365

ID: 9b872db8-413f-5767-96c2-f4f79e169395

STIX ID: report--9b872db8-413f-5767-96c2-f4f79e169395

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

Lexfo discovered that an attacker accidentally exposed a public HTTP directory (via 'python3 -m http.server') containing a readable .bash_history, which revealed three active Evilginx-based Microsoft 365 phishing campaigns. The report explains how Evilginx acts as an adversary-in-the-middle to capture session cookies and bypass MFA, outlines the attack flow, lists mitigations (phishing-resistant MFA, conditional access, token protection, domain intelligence, and user training), and highlights OPSEC lessons and the value of scanning exposed infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.