Open Directory Exposes Three Evilginx Phishing Operators
ID: 496349e6-da39-5dfd-902e-5f957900e251
STIX ID: report--496349e6-da39-5dfd-902e-5f957900e251
Feed Name: Infosecurity Magazine (News)
French firm Lexfo found a misconfigured public Python HTTP server exposing phishing configurations, credential logs, RMM tools and operator session files tied to three actors (codemado, mail-argenta, saroula01). The activity included an Evilginx-based AiTM proxy, a custom bulk-mailer and infostealer artefacts, and a device-code OAuth campaign that ran for over a year, capturing tokens from 218 corporate victims across 12 countries and allowing tokens to be refreshed repeatedly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
