logo

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

ID: 24408505-add5-5fdf-9689-dffc90cf2e81

STIX ID: report--24408505-add5-5fdf-9689-dffc90cf2e81

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

Executive summary: French firm Lexfo uncovered three interlinked Microsoft 365 phishing operations leveraging public Evilginx forks and an OAuth device-code lure to harvest session tokens and defeat MFA; operators (codemado, mail-argenta, saroula01) captured hundreds of corporate mailboxes (218 logged captures), stored long-lived refresh tokens, and exposed phishing configs, credential logs, RMM installers and repos (notable infrastructure: picis.net, romnor.ca, IP 185.163.204.7), while the report calls out AI-assisted tooling and provides mitigations including blocking device-code flow via Conditional Access, enforcing phishing-resistant MFA, and monitoring Entra sign-in logs and Original transfer method.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.