216.73.217.24

Inside a Global Procurement-Themed AiTM Phishing Campaign

· Published 22/07/2026 02:59

Export JSON

Essential information

Published
22/07/2026 02:59
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
aitm phishing credential theft domain compromise evilproxy flowerstorm kali365 mfa bypass procurement lures session hijacking
Related entities
21 indicators, 21 observables

Description

A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple kits including , , and to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

External references