Executive Summary
In April 2026, a misconfigured server exposed three active Microsoft 365 phishing operations utilizing customized versions of the Evilginx adversary-in-the-middle (AiTM) proxy. The exposed server, left with directory listing enabled, revealed comprehensive toolkits, including phishing configurations, credential logs, and remote management tools. Analysis traced these operations to an Egyptian actor known as 'codemado,' who cloned and modified public Evilginx repositories to orchestrate sophisticated phishing campaigns targeting corporate mailboxes. The campaigns effectively bypassed multi-factor authentication (MFA) by proxying live login sessions and abusing legitimate Microsoft sign-in flows, allowing attackers to capture session cookies and maintain prolonged access to compromised accounts.
This incident underscores the evolving sophistication of phishing-as-a-service platforms and the critical need for organizations to implement robust security measures beyond traditional MFA. The exposure of these operations highlights the importance of continuous monitoring and auditing of authentication processes to detect and mitigate unauthorized access attempts. As attackers refine their techniques to circumvent existing defenses, organizations must stay vigilant and adapt their security strategies accordingly.
Why This Matters Now
The exposure of these sophisticated phishing operations highlights the urgent need for organizations to enhance their security measures beyond traditional MFA, as attackers continue to develop methods to bypass existing defenses.
Attack Path Analysis
An attacker utilized a misconfigured Python web server to host an Evilginx phishing operation targeting Microsoft 365 users. By proxying legitimate login flows, the attacker captured credentials and session tokens, bypassing multi-factor authentication. The attacker then escalated privileges by accessing additional services within the compromised accounts. Lateral movement was achieved by leveraging the stolen credentials to access other corporate mailboxes and services. Command and control were maintained through persistent access to the compromised accounts, allowing continuous monitoring and data collection. Exfiltration involved transferring sensitive data from the compromised accounts to external servers. The impact included unauthorized access to corporate communications, potential data breaches, and financial loss.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a misconfigured Python web server to host an Evilginx phishing operation, capturing Microsoft 365 credentials and session tokens.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Adversary-in-the-Middle
Multi-Factor Authentication Interception
Steal Web Session Cookie
Application Layer Protocol: Web Protocols
User Execution: Malicious Link
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for managing firewalls are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Microsoft 365 phishing operations directly threaten financial institutions' customer credentials, triggering compliance violations under PCI and NIST frameworks with significant data exfiltration risks.
Health Care / Life Sciences
Evilginx phishing targeting Microsoft 365 compromises patient data access, violating HIPAA encryption requirements and enabling lateral movement through healthcare system networks.
Information Technology/IT
IT sector faces elevated risks from exposed phishing toolkits enabling privilege escalation and command-and-control operations across multi-cloud environments requiring zero trust segmentation.
Government Administration
Government agencies using Microsoft 365 are vulnerable to sophisticated phishing operations that bypass traditional security, requiring enhanced threat detection and anomaly response capabilities.
Sources
- Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365https://thehackernews.com/2026/07/misconfigured-server-reveals-three.htmlVerified
- Evilginx AiTM Attacks Bypass MFA by Stealing Microsoft 365 Sessionshttps://diamatix.com/evilginx-aitm-microsoft-365-session-theft/Verified
- EvilTokens ramps up device code phishing targeting Microsoft 365 usershttps://www.helpnetsecurity.com/2026/03/31/eviltokens-phishing-microsoft-365/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it could likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit misconfigured servers for phishing operations could likely be constrained, reducing the risk of credential harvesting.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within compromised accounts could likely be limited, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the organization could likely be constrained, reducing the risk of widespread compromise.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain persistent access and monitor data could likely be limited, reducing the duration of unauthorized activities.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external servers could likely be constrained, reducing the risk of data breaches.
The overall impact of unauthorized access and data breaches could likely be reduced, minimizing potential financial loss and reputational damage.
Impact at a Glance
Affected Business Functions
- Email Communication
- Document Management
- Collaboration Tools
- Cloud Storage
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of corporate emails, internal documents, and sensitive communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access between workloads and services, limiting lateral movement opportunities.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalous behaviors.
- • Enforce East-West Traffic Security to secure internal communications and detect unauthorized access attempts.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads in real-time.



