codemado is an Egyptian cybercriminal operator active since at least 2018 and associated with Microsoft 365 adversary-in-the-middle phishing, session theft, and post-compromise access operations. Known aliases include MaDoO, MaDosc, and MADO. The actor has roots in hacking and VoIP forums and has been linked to a commercially distributed bulk-mailing and phishing tool called MaDoO Blaster, which appears to be monetized beyond the actor’s own operations and has been associated as a supplier/client component within the broader phishing ecosystem known as The Quarry. codemado operated a full Evilginx-based AiTM phishing platform targeting Microsoft 365 accounts, using infrastructure designed to bypass multi-factor authentication by stealing authenticated sessions and tokens. The operation employed anti-bot filtering, phishing lure rotation, SMTP validation workflows, and cloud-tunneled concealment of backend infrastructure. Confirmed victimization included corporate Microsoft 365 accounts, including at least one victim in France and another in North America. Beyond credential and session capture, codemado maintained a substantial post-compromise toolkit. The actor used multiple remote monitoring and management tools to preserve access on victim systems and exposed evidence of malware delivery and remote-access tooling, including AsyncRAT-linked activity and Hidden VNC-related references. Operational artifacts also showed automated collection of combolists and validation of compromised SMTP accounts for use in phishing distribution. The actor’s capabilities span initial access through phishing, session hijacking, credential theft, persistence, defense evasion, and post-exploitation. codemado also appears to have developed or operated phishing enablement tooling for bulk email delivery, personalized lure generation, and filter evasion, indicating both operator and supplier roles within the cybercriminal ecosystem. The dominant motivation is financial.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates an Evilginx adversary-in-the-middle phishing platform targeting Microsoft 365 and is linked as a supplier/client to a broader phishing-as-a-service ecosystem.
Cybercriminal phishing operator running an adversary-in-the-middle M365 phishing platform on picis.net, using Evilginx infrastructure, RMM tooling, loaders, and bulk phishing capabilities via MaDoO Blaster.
Operating a Microsoft 365 adversary-in-the-middle phishing campaign using a custom Evilginx fork to capture credentials and session tokens from primarily corporate mailboxes, while monetizing access with a bulk mailer.
Runs an Evilginx-based adversary-in-the-middle phishing operation targeting Microsoft 365 corporate accounts, uses anti-bot filtering, Telegram-based combo harvesting, compromised SMTP accounts for delivery, and multiple RMM tools for post-compromise persistence. Also develops/promotes MaDoO Blaster as a bulk-mailing tool.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.