Inside a Global Procurement-Themed AiTM Phishing Campaign
Essential information
- Published
- 22/07/2026 02:59
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- aitm phishing credential theft domain compromise evilproxy flowerstorm kali365 mfa bypass procurement lures session hijacking
- Related entities
- 21 indicators, 21 observables
Description
A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.