Breaking Down 3 Phishing Operations: How Misconfigured Servers Led to a Web of Attacks (2026)

In the realm of cybersecurity, the revelation of misconfigured servers has once again exposed the vulnerabilities that lurk in the shadows of the digital landscape. This time, the spotlight shines on three Evilginx phishing operations targeting Microsoft 365, a stark reminder of the ongoing battle between attackers and defenders. The story begins with a simple yet critical oversight: a Python web server left running on a public port with directory listing enabled, inadvertently revealing a trove of sensitive information. This single lapse in security was the key that unlocked a deeper, more insidious attack surface.

What makes this incident particularly intriguing is the intricate web of connections that emerged. The French security firm Lexfo, through meticulous analysis, uncovered not just one, but three interconnected phishing operations. Each of these operations was a custom fork of the open-source Evilginx proxy, cloned from public GitHub repositories. The largest of these campaigns had been running for over a year, targeting corporate mailboxes with a precision that suggests a sophisticated understanding of organizational structures.

One of the most striking aspects of this discovery is the diversity of techniques employed to bypass Multi-Factor Authentication (MFA). The first operator used a proxy to intercept live logins, while the second abused a legitimate Microsoft sign-in flow. These distinct approaches highlight the multifaceted nature of modern phishing attacks and the need for tailored defenses.

The implications of this discovery are far-reaching. The exposure of phishing configurations, credential-harvesting logs, and RMM installers on the misconfigured server is akin to a full confession. It provides a window into the inner workings of these operations, from the use of Evilginx proxies to the deployment of SimpleHelp remote consoles. The server, located in Budapest, served as a central hub for these activities, cataloged during a routine internet scan in late April 2026.

The operator, identified as an Egyptian actor known as codemado, has been active in VoIP and hacking forums since 2018. His campaign, which began on April 20, continued until the directory was discovered on April 30, with fresh subdomains and renewed wildcard certificates emerging weeks later. The repeated captures of the same accounts from different IPs suggest a methodical approach to refreshing stolen tokens as they aged out.

What's particularly fascinating is the ecosystem that these operations are part of. In June 2026, SOCRadar documented a phishing-as-a-service ecosystem called The Quarry, run by a developer known as RockyBelling. This ecosystem, sold to close to 200 operators, includes tools like MaDoO Blaster, which codemado used to monetize his access. The relationship between these operators and The Quarry is complex, with some promoting third-party tools and others potentially having direct ties.

The use of AI in these operations is another intriguing aspect. Lexfo's CTI team found signs of AI-assisted development across all three operations, though the strength of this integration varies. The use of AI in generating custom code and scripts is a clear indicator of the evolving nature of cyberattacks, where technology is increasingly being leveraged to automate and enhance malicious activities.

From a defensive perspective, the implications are clear. The two techniques employed by these operators do not share a common fix. While phishing-resistant MFA, FIDO2, or passkeys can shut down the Evilginx side by binding the sign-in to the real domain, they do not address the device code abuse. The lever for addressing this lies in Conditional Access policies, which can block device code flow and reevaluate stolen tokens from outside allowed ranges.

The report highlights the importance of continuous monitoring and detection. Refresh-token grants from the Microsoft Office client ID d3590ed6-52b3-4102-aeff-aad2292ab01c in Entra sign-in logs should be watched for anomalies, particularly when the desktop client is not in normal use. Additionally, hunting for RMM tooling on endpoints can help identify persistence mechanisms deployed by these operators.

In conclusion, this incident serves as a stark reminder of the ever-evolving nature of cyber threats and the need for vigilance and adaptability in defense. The barrier to launching a successful campaign has fallen to near zero, and the Lexfo CTI team expects this class of attack to become significantly more common over the coming months. As the digital landscape continues to transform, the battle between attackers and defenders will only intensify, requiring a proactive and innovative approach to cybersecurity.

Breaking Down 3 Phishing Operations: How Misconfigured Servers Led to a Web of Attacks (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rev. Leonie Wyman

Last Updated:

Views: 6647

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Rev. Leonie Wyman

Birthday: 1993-07-01

Address: Suite 763 6272 Lang Bypass, New Xochitlport, VT 72704-3308

Phone: +22014484519944

Job: Banking Officer

Hobby: Sailing, Gaming, Basketball, Calligraphy, Mycology, Astronomy, Juggling

Introduction: My name is Rev. Leonie Wyman, I am a colorful, tasty, splendid, fair, witty, gorgeous, splendid person who loves writing and wants to share my knowledge and understanding with you.