Exposed! How 3 Evilginx Phishing Operators Stole Corporate Data (AiTM Attacks Explained) (2026)

The recent discovery of an exposed Python HTTP server, accessible via an open directory, has shed light on a sophisticated phishing operation. This server, located on a virtual private server in Budapest, contained a treasure trove of sensitive information, including phishing configurations, credential logs, remote management installers, and even Telegram session files. The threat actor behind this operation, codemado, was found to be utilizing an Evilginx-based adversary-in-the-middle (AiTM) platform to target corporate Microsoft 365 accounts.

What's particularly intriguing is the involvement of three distinct actors, each contributing to the phishing ecosystem. The first actor, codemado, is linked to an Egyptian operator who has been active on hacking forums since 2018. This Egyptian operator possesses a range of remote monitoring and management (RMM) tools, including ScreenConnect, SimpleHelp, and a custom bulk-mailer called MaDoO Blaster. The second actor, mail-argenta, is traced through infostealer logs and is believed to be a Nigerian individual.

The third actor, saroula01, stands out for their extensive use of generative AI in building phishing tools. Evidence of AI co-author metadata in saroula01's commits and a saved development session in mail-argenta's repository suggest a reliance on AI in the creation of these phishing frameworks. Interestingly, saroula01's operation was the largest, with a Device Code campaign that ran undetected for over a year, accumulating 218 confirmed victims across 12 countries, primarily targeting corporate entities.

The ease of access to these phishing tools is concerning. The components required to run a functional AiTM campaign are readily available, either freely on GitHub or sold on Telegram for a few hundred dollars. This accessibility has significantly lowered the barrier to entry for threat actors, making it crucial for defenders to remain vigilant. Lexfo's research emphasizes the importance of disabling device code authentication when not necessary to prevent potential session hijacking or Device Code Flow abuse, as any actor can potentially bypass multi-factor authentication (MFA) through these methods.

Exposed! How 3 Evilginx Phishing Operators Stole Corporate Data (AiTM Attacks Explained) (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Errol Quitzon

Last Updated:

Views: 5845

Rating: 4.9 / 5 (79 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.