logo

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

ID: 79adb421-05f2-56b3-aa8a-9e5f14d8ed6b

STIX ID: report--79adb421-05f2-56b3-aa8a-9e5f14d8ed6b

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-11

Author: Microsoft Defender Security Research Team and Microsoft Threat Intelligence

...
...

Microsoft Defender Research observed a multi-step phishing campaign (April 14–16, 2026) that targeted over 35,000 users across more than 13,000 organizations—primarily in the United States—using code-of-conduct-themed lures, enterprise-style PDFs with embedded links, CAPTCHA gating, intermediate staging pages, and an adversary-in-the-middle (AiTM) sign-in flow to capture authentication tokens; the report provides IoCs, hunting queries, and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.