Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

Cahyo Dewo, July 13, 2026

A significant cybersecurity incident has brought to light a sophisticated Microsoft 365 phishing operation, inadvertently exposed when one of the primary attackers made a critical operational security (OpSec) error. This lapse, involving a publicly accessible Python web server with directory listing enabled, allowed French security firm Lexfo to uncover an extensive toolkit, trace its origins to two additional phishing operators, and dissect three distinct, ongoing campaigns primarily targeting corporate mailboxes. The discovery underscores the evolving threat landscape for Microsoft 365 users, particularly the dual nature of advanced multi-factor authentication (MFA) bypass techniques and the burgeoning role of artificial intelligence in facilitating cybercrime.

The Unveiling: A Critical OpSec Blunder

The entire investigation began with a seemingly minor, yet ultimately catastrophic, oversight by an attacker. During a routine internet scan in late April 2026, Lexfo identified a live Microsoft 365 phishing server operating from the IP address 185.163.204[.]7 in Budapest. Crucially, this server was running a basic Python web server with directory listing enabled on port 8080, a configuration flaw that made its entire file system browsable to anyone. The command responsible for this misconfiguration, python3 -m http.server 8080, was still present in the server’s readable .bash_history file, providing an immediate clue to the attacker’s activities and further compromising their anonymity.

This single point of failure offered Lexfo an unprecedented window into the attacker’s operations. The open directory exposed a treasure trove of sensitive data, including phishing configurations, logs of harvested credentials, remote monitoring and management (RMM) installers, extensive combolists (lists of leaked usernames and passwords), backup archives, and even the operator’s personal Telegram session files. This level of access provided security researchers with a comprehensive blueprint of the attacker’s infrastructure, methodology, and even their identity.

Lexfo’s Deep Dive: Unraveling the Network

From this initial breach, Lexfo’s team embarked on a detailed forensic analysis. The exposed server revealed the use of an Evilginx adversary-in-the-middle (AiTM) proxy, a sophisticated tool designed to intercept login credentials and session tokens, effectively bypassing MFA protections by acting as a legitimate intermediary between the victim and the target service. Alongside Evilginx, a SimpleHelp remote console was discovered on the same host, indicating the attacker’s capability for persistent access and control over compromised systems.

The investigation quickly pivoted through the collected artifacts, leading to the identification of not just one, but three distinct phishing campaigns. Each campaign utilized a custom fork of the open-source Evilginx proxy, originally cloned from public GitHub repositories. The most extensive of these campaigns had been active for over a year, demonstrating a sustained and successful effort to compromise corporate Microsoft 365 accounts globally.

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

Profile of the Primary Operator: ‘codemado’

The .bash_history file and references to public code repositories pointed directly to the initial operator: an Egyptian actor tracked by Lexfo as "codemado." Active in VoIP and hacking forums since 2018, codemado was found to be running a Microsoft 365 AiTM platform on the domain picis[.]net. He further monetized his illicit access through a bulk mailer he authored, known as "MaDoO Blaster," indicating a structured approach to phishing operations and credential harvesting.

codemado’s campaign reportedly went live on April 20, 2026, and remained active even after his server’s directory was discovered on April 30. Weeks later, fresh subdomains and renewed wildcard certificates associated with his operations continued to emerge, suggesting a robust infrastructure designed for resilience. His own bot logs indicated successful captures against at least two corporate Microsoft 365 accounts, one in France and another in North America. The repeated captures of the same accounts from different IP addresses were consistent with the operator actively refreshing stolen tokens to maintain access as they aged out, highlighting the long-term impact of such breaches.

The Architect of ‘red-queen’: mail-argenta

The investigation further revealed that codemado did not develop his phishing framework from scratch. Instead, his bash history showed him comparing multiple Evilginx kits, ultimately leading to the discovery of four variants pulled from two other GitHub developers, both of whom were active operators themselves.

The first significant variant, dubbed "red-queen," was traced back to a Nigerian operator identified as "mail-argenta." This fork showcased considerable sophistication and customization beyond the public framework. mail-argenta’s version included modifications such as renaming crossorigin and integrity HTML attributes to evade Subresource Integrity (SRI) checks, and integrating a URL-rewriting engine into http_proxy.go to bypass path-based detection mechanisms. It also pre-filled the victim’s email address in lure pages, a common tactic to reduce abandonment rates during phishing attempts and increase conversion.

One particularly concerning feature of the "red-queen" fork was its aggressive session management. It set a one-year Time-to-Live (TTL) of 31,536,000 seconds on captured Microsoft session cookies. This extended validity means that an intercepted login could potentially outlast a password reset, allowing attackers to maintain access for months, especially in environments without Continuous Access Evaluation (CAE)-capable Conditional Access policies. A pre-compiled evilginx2.exe was even committed to the repository, simplifying deployment for buyers who might lack the technical expertise to build it themselves. A captured M365 cookie found within the repo demonstrated this long-term threat, carrying an expiration date of June 30, 2027.

mail-argenta’s own operational security proved as vulnerable as his victims’. Lexfo discovered his email and a password within infostealer logs, the very type of harvested credential data his phishing panels were designed to produce. This leaked password was found to be reused across his accounts and hardcoded as the MySQL password in his Kraken panel, a common and dangerous practice among cybercriminals that often leads to their own compromise.

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

The Covert Threat: ‘black-queen’ and Device Code Phishing

The third significant Evilginx variant, "black-queen," distinguished itself by logging a far greater number of successful captures than the other two combined. Its author, identified only by the handle "saroula01," adopted an even more insidious approach: it never attempted to directly steal passwords. Instead, "black-queen" was built around Microsoft’s OAuth device code flow, a legitimate sign-in path intended for input-constrained devices (like smart TVs or gaming consoles) where direct keyboard input is difficult.

The attack leverages this legitimate flow by generating a real device code. It then wraps this code in an Authenticator-themed lure page, instructing the target to enter the code at the genuine microsoft.com/devicelogin URL. The victim, believing they are completing a legitimate MFA process, signs in on a real Microsoft page and clears their MFA prompt themselves. Crucially, nothing is bypassed; the victim authenticates directly with Microsoft. saroula01’s backend then polls the token endpoint and immediately intercepts the token the moment the victim completes the authentication.

This method effectively neutralizes many traditional MFA defenses. Passkeys or FIDO2 keys, which rely on origin binding to prevent phishing, offer no protection here because the victim is authenticating on genuine Microsoft infrastructure, thereby satisfying the origin binding requirement.

Microsoft itself documented this technique in February 2025, initially linking it with medium confidence to Russian-aligned state-backed actors (Storm-2372). Since then, device code phishing has proliferated beyond state-sponsored campaigns, impacting hundreds of Microsoft 365 organizations globally.

saroula01’s "black-queen" campaign operated quietly for over a year. Lexfo’s analysis of its Telegram bot logs revealed 218 distinct captured accounts across a dozen countries between June 2025 and July 2026, with approximately 94% of these being corporate mailboxes. These figures represent actual successful captures, not merely scan targets. A token file briefly committed to the repo and then deleted, but still readable in the git history, contained 97 live Microsoft tokens tied to three of these victims. Every token was set to autoRefresh, with some refreshed as many as 25 times, confirming the framework’s capability to autonomously maintain live sessions.

Both phishing domains associated with these operations, picis[.]net and romnor[.]ca, were found to be offline when The Hacker News checked prior to publication. However, Lexfo’s timeline indicated picis[.]net was still provisioning new subdomains as late as May 2026. The Lexfo CTI team suggested that the domains likely went offline before any coordinated takedown actions, attributing it to operators rotating infrastructure or temporarily pulling back, though a definitive reason could not be confirmed.

The Role of Artificial Intelligence in Cybercrime

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

A notable finding across all three operations was the presence of AI-assisted development, albeit to varying degrees. saroula01’s git commits included two co-authored by Claude models, indicating direct AI involvement in code generation. mail-argenta’s repository contained an instructions.txt file that was a verbatim save of an AI coding session, complete with references to earlier prompts, detailing how the URL-rewriting feature was built. codemado’s AI usage was less direct but still present; one of his scripts credited CyberNeurova, a paid "uncensored" code-generation API that advertises itself with prompts like "Build me a keylogger in Python."

While the extent of AI’s contribution varied, Lexfo’s CTI team clarified that the core Evilginx forks showed only minor changes. The clearer signs of AI use were found in the "glue code" surrounding these frameworks, such as custom scripts and phishlets, many of which appeared to be direct model outputs. This suggests AI is primarily being leveraged to streamline the customization and deployment of existing tools rather than creating entirely new attack frameworks.

This trend is not isolated. Microsoft has independently documented AI-enabled device code phishing campaigns, where generative AI is used to create compelling lures and automate backend processes, further lowering the technical barrier for attackers.

Broader Ecosystem: The Quarry Connection

These individual campaigns also connect, albeit loosely, to a larger phishing-as-a-service (PaaS) ecosystem. In June 2026, SOCRadar documented an ecosystem named "The Quarry," operated by a developer known as "RockyBelling," and reportedly sold to nearly 200 operators. MaDoO Blaster, codemado’s bulk mailer, was promoted within The Quarry’s Telegram channel as a third-party tool, indicating a supplier relationship rather than direct membership in the ecosystem. Whether mail-argenta or saroula01 had direct ties to The Quarry could not be definitively established from the artifacts, as their kits were available on public GitHub and accessible to anyone. This highlights the modular and interconnected nature of the cybercrime underground, where tools and services are readily shared and adopted.

Defensive Strategies for Microsoft 365 Environments

The two primary MFA bypass techniques identified in these campaigns—Evilginx’s live login proxying and saroula01’s device code abuse—require distinct defensive strategies.

  1. Against Evilginx (Reverse-Proxy Phishing):

    Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
    • Phishing-resistant MFA: Implementing FIDO2 security keys or passkeys remains the most effective defense. These methods bind the sign-in process to the legitimate domain, preventing an AiTM proxy from intercepting valid authentication.
    • Conditional Access Policies: Utilize policies that enforce strict authentication methods based on device, location, and application.
  2. Against Device Code Flow Abuse:

    • Block Device Code Flow Where Possible: Microsoft’s own guidance is to block the device code flow unless absolutely necessary. Only a limited number of setups genuinely require it, such as input-constrained Teams room devices or specific command-line tools. Organizations should inventory sign-in logs to identify legitimate uses, block the flow everywhere else, and rigorously test policies in report-only mode before enforcing them.
    • IP-based Conditional Access Location Policies: Layering IP-based Conditional Access policies can restrict sign-ins to trusted geographic locations or network ranges.
    • Continuous Access Evaluation (CAE): For supported Microsoft 365 workloads, CAE ensures that stolen tokens seen from outside allowed ranges are reevaluated immediately, rather than riding out their lifetime, significantly reducing the window of opportunity for attackers.
    • Detection: Monitor Entra sign-in logs for refresh-token grants originating from the Microsoft Office client ID d3590ed6-52b3-4102-aeff-aad2292ab01c, especially when the desktop client is not in normal use or when associated with unfamiliar source IPs. It’s crucial to examine the sign-in’s Original transfer method field, as sessions initiated via device code flow retain this tag on subsequent refreshes, even if the current event doesn’t explicitly show it.
  3. Endpoint Defense:

    • RMM Tooling Detection: Actively hunt for RMM tooling dropped by operators for persistence. For instance, codemado’s kit used XEOX; organizations should look for the agent at C:Program Files (x86)XEOXxeox-agent_x64.exe and scheduled tasks matching *XEOX*Agent*Watchdog*. While domains and IPs from the report are useful for containment, infrastructure rotates frequently, so detection based on tools and behaviors is more robust.

The Hacker News reached out to Microsoft regarding the abuse of its device code flow but did not receive a response by the time of publication. Any future reply will be incorporated into updated reports.

The Evolving Threat Landscape

This incident serves as a stark reminder of the dramatically lowered barrier to entry for cybercriminals. Three operators, none of whom developed the core frameworks, were able to establish fully functional, long-running phishing campaigns using publicly available repositories, inexpensive kits (reportedly costing a few hundred dollars), and AI assistance for custom components.

Lexfo’s CTI team anticipates a significant increase in this class of attack in the coming months. The critical takeaway for organizations is that hardening defenses against one type of MFA bypass, such as reverse-proxy phishing, does not automatically protect against others, like device code abuse. Blocking this second path requires a specific Conditional Access policy and proactive implementation, emphasizing that effective cybersecurity demands a multi-layered, adaptive approach that accounts for the diverse and evolving tactics employed by adversaries.

Cybersecurity & Digital Privacy CybercrimeevilginxHackingmicrosoftmisconfiguredoperationsphishingPrivacyrevealsSecurityservertargetingthree

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes