logo

Inside the UPMI Phishing-as-a-Service Platform

ID: 956756ca-f2b5-5734-b75a-fa0a3b9ec33f

STIX ID: report--956756ca-f2b5-5734-b75a-fa0a3b9ec33f

Feed Name: Ctrl-Alt-Int3l

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

Ctrl-Alt-Intel recovered and analysed the complete source code of "UPMI ULTIMATE", an AI-assisted Phishing-as-a-Service platform that automates reconnaissance, multi-method email delivery (Direct MX / Office365 relay / Microsoft Graph), encrypted LinkShield redirects with CAPTCHA gating, and Evilginx reverse proxies that capture credentials and live session tokens to bypass MFA; the exposed master server revealed licensing, collective intelligence, operator dashboard controls, and numerous IOCs tied to active deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.