This article describes an adversary-in-the-middle phishing campaign that uses compromised, often aged domains and fake document workflows to steal authenticated sessions from targeted organizations. The actor rotates between Evilginx, EvilProxy, FlowerStorm, and Kali365 while impersonating platforms such as Microsoft, OpenGov, ConstructConnect, and the European Investment Bank to capture credentials, MFA-protected access, cookies, and session tokens. #EvilProxy #FlowerStorm #Kali365 #Evilginx #OpenGov #ConstructConnect #EuropeanInvestmentBank
Keypoints
- The campaign uses adversary-in-the-middle (AiTM) phishing to intercept active sessions rather than simply stealing passwords.
- Initial emails are sent from compromised organizational accounts to make the lures appear legitimate and increase trust.
- The lures are themed around professional workflows such as RFIs, bid invitations, and shared project documents.
- Victims are led through fake download pages, CAPTCHA checks, and cloned login portals that impersonate trusted services.
- The actor uses multiple phishing kits, including Evilginx, EvilProxy, FlowerStorm/Storm-1167, and Kali365, to increase resilience and scale.
- Compromised aged domains are used as infrastructure, often with injected PHP content and RDGA-like naming patterns.
- The campaign targets universities, enterprises, and multinational institutions, including European Union and United Nations-related organizations.
MITRE Techniques
- [T1566 ] Phishing – The actor sends lure emails from compromised accounts to trick recipients into opening links and interacting with fake workflows (’emails sent from previously compromised accounts’ and ‘phishing emails sent to targeted victims’).
- [T1584.001 ] Compromise Infrastructure: Domains – The campaign relies on aged or dormant domains that appear compromised and are repurposed to host fake download and login pages (‘likely compromised’ and ‘the actor may have compromised aged domains’).
- [T1133 ] External Remote Services – Victims are funneled into cloned Microsoft and other sign-in pages so the attacker can obtain authenticated access through the login flow (‘intercept MFA-protected sessions in real time’ and ‘establish authenticated sessions’).
- [T1056 ] Input Capture – The fake portals collect credentials, email addresses, and MFA-related login information as users enter them (‘when a user enters their credentials and completes MFA’).
- [T1111 ] Multi-Factor Authentication Interception – The actor captures MFA-protected sessions and relays authentication in real time to bypass MFA controls (‘capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – The phishing infrastructure uses web-based portals, CAPTCHA pages, and cloned authentication sites over HTTP/S to deliver the attack (‘fake document download pages’, ‘CAPTCHA completion’, and ‘fake Microsoft authentication page’).
- [T1021 ] Remote Services – The attacker uses harvested cookies and session tokens to operate within authenticated services without re-entering credentials (‘session tokens and cookies were intercepted by the attacker’).
Indicators of Compromise
- [Domains ] fake download and phishing infrastructure – testserveren[.]com, barifurniture[.]net, and other compromised domains such as sohantraders[.]com and vresortsliving[.]com
- [Domains ] FlowerStorm/Storm-1167 RDGA-like domains – usersatisfactionlab[.]de, sustainablegrowthlaunch[.]de, and innovativegrowthstrategy[.]de
- [Domains ] EvilProxy phishing domains – q1evaluationperformance[.]net, corporatetermscompliance[.]com, and assessmentevaluationreport[.]com
- [Domains ] Kali365 infrastructure – duemineral[.]uk
- [URL paths ] victim-specific phishing paths – /user@company[.]com/ and similar email-address embedded paths
- [File names ] injected malicious web content – index.php