Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
ID: 79adb421-05f2-56b3-aa8a-9e5f14d8ed6b
STIX ID: report--79adb421-05f2-56b3-aa8a-9e5f14d8ed6b
Feed Name: Microsoft Security
Date Published: 2026-05-04
Date Updated: 2026-05-11
Author: Microsoft Defender Security Research Team and Microsoft Threat Intelligence
Microsoft Defender Research observed a multi-step phishing campaign (April 14–16, 2026) that targeted over 35,000 users across more than 13,000 organizations—primarily in the United States—using code-of-conduct-themed lures, enterprise-style PDFs with embedded links, CAPTCHA gating, intermediate staging pages, and an adversary-in-the-middle (AiTM) sign-in flow to capture authentication tokens; the report provides IoCs, hunting queries, and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
