Exposed: How 3 Evilginx Phishing Operators Stole Corporate Credentials (AiTM Attacks Explained) (2026)

The recent exposure of a misconfigured server has shed light on a sophisticated phishing operation, revealing a three-actor ecosystem with a shared codebase. This incident highlights the ease of access to advanced phishing tools and the potential for widespread impact.

The server, accessible through an open directory, contained sensitive information such as phishing configurations, credential logs, and remote management installers. The threat actor, codemado, was found to be operating an Evilginx-based adversary-in-the-middle (AiTM) platform targeting corporate Microsoft 365 accounts. This discovery links codemado to an Egyptian operator active on hacking forums since 2018, suggesting a potential collaboration or shared interests.

One of the operators, mail-argenta, was traced through infostealer logs and reused credentials, indicating a Nigerian individual's involvement. The other operator, saroula01, built a framework abusing the OAuth Device Code Flow, a legitimate Microsoft feature. Interestingly, saroula01's operation was the largest, running for over a year without detection, and accumulating 218 confirmed victims across 12 countries.

The use of generative AI in building phishing tools is evident, with AI co-author metadata found in saroula01's commits and a saved development session in mail-argenta's repository. This trend is concerning, as it lowers the barrier to entry for malicious actors, making it easier to create sophisticated phishing campaigns.

Lexfo's research also connects codemado's MaDoO Blaster to The Quarry, a phishing-as-a-service (PaaS) ecosystem. The ease of access to these tools and services is alarming, as it allows actors to quickly deploy and adapt their phishing campaigns. Defenders are urged to assume that any actor can bypass MFA through session hijacking or Device Code Flow abuse and to disable device code authentication where possible.

This incident serves as a stark reminder of the evolving threat landscape and the need for constant vigilance in cybersecurity. As the barriers to entry for phishing operations continue to decrease, organizations must remain proactive in protecting their systems and data.

Exposed: How 3 Evilginx Phishing Operators Stole Corporate Credentials (AiTM Attacks Explained) (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Dong Thiel

Last Updated:

Views: 6598

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Dong Thiel

Birthday: 2001-07-14

Address: 2865 Kasha Unions, West Corrinne, AK 05708-1071

Phone: +3512198379449

Job: Design Planner

Hobby: Graffiti, Foreign language learning, Gambling, Metalworking, Rowing, Sculling, Sewing

Introduction: My name is Dong Thiel, I am a brainy, happy, tasty, lively, splendid, talented, cooperative person who loves writing and wants to share my knowledge and understanding with you.