logo

Open Directory Exposes Three Evilginx Phishing Operators

ID: 496349e6-da39-5dfd-902e-5f957900e251

STIX ID: report--496349e6-da39-5dfd-902e-5f957900e251

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-07-13

Date Updated: 2026-07-16

...
...

French firm Lexfo found a misconfigured public Python HTTP server exposing phishing configurations, credential logs, RMM tools and operator session files tied to three actors (codemado, mail-argenta, saroula01). The activity included an Evilginx-based AiTM proxy, a custom bulk-mailer and infostealer artefacts, and a device-code OAuth campaign that ran for over a year, capturing tokens from 218 corporate victims across 12 countries and allowing tokens to be refreshed repeatedly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.