logo

The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions

ID: 8f0b1a10-34a0-5b59-a7c7-b0380a5b39c5

STIX ID: report--8f0b1a10-34a0-5b59-a7c7-b0380a5b39c5

Feed Name: Infoblox Threat Intel Blog

Threat Score
75/100

Date Published: 2026-07-21

Date Updated: 2026-08-06

Author: Infoblox Threat Intel

...
...

This report analyzes an active adversary-in-the-middle (AiTM) phishing campaign targeting universities, enterprises, and international organizations. The actor compromises aged domains and injects PHP-based fake document portals, then uses staged interactions and multiple PhaaS AiTM kits (EvilProxy, FlowerStorm/Storm-1167, Kali365) to capture credentials, MFA tokens, and session cookies—enabling authenticated session takeover; the report provides indicators and domain patterns useful for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.