The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions
ID: 8f0b1a10-34a0-5b59-a7c7-b0380a5b39c5
STIX ID: report--8f0b1a10-34a0-5b59-a7c7-b0380a5b39c5
Feed Name: Infoblox Threat Intel Blog
This report analyzes an active adversary-in-the-middle (AiTM) phishing campaign targeting universities, enterprises, and international organizations. The actor compromises aged domains and injects PHP-based fake document portals, then uses staged interactions and multiple PhaaS AiTM kits (EvilProxy, FlowerStorm/Storm-1167, Kali365) to capture credentials, MFA tokens, and session cookies—enabling authenticated session takeover; the report provides indicators and domain patterns useful for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
