Attackers ran a procurement-themed adversary-in-the-middle phishing campaign against universities, enterprises, multinational institutions, and organizations linked to the European Union and United Nations, using compromised Outlook accounts to resend lures from trusted internal or partner addresses. Victims were directed to fake document download portals with CAPTCHA stages and cloned Microsoft 365 login pages impersonating brands including Microsoft, OpenGov, ConstructConnect, and the European Investment Bank, enabling the theft of credentials, session cookies, and MFA-authenticated tokens in real time.
Researchers said the operation relied on reverse-proxy phishing kits including EvilProxy, FlowerStorm/Storm-1167, and Kali365 to bypass MFA and gain access to Outlook, SharePoint, and other Microsoft 365 resources. The infrastructure favored aged or compromised domains, RDGA-style phishing domains, phishing subdomain conventions, and injected PHP content on dormant websites, indicating an effort to evade detection by avoiding newly registered infrastructure; defenders were urged to use DNS and passive DNS visibility, Microsoft 365 sign-in monitoring, and conditional access controls because MFA alone does not stop session hijacking.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In May 2026, attackers ran an adversary-in-the-middle phishing campaign using compromised Outlook mailboxes to resend procurement-themed lures from trusted addresses. The operation targeted universities, enterprises, multinational institutions, and organizations linked to the European Union and United Nations to steal Microsoft 365 session cookies and MFA-authenticated tokens.
Infoblox disclosed a detailed analysis of a sophisticated 2026 procurement-themed AiTM phishing campaign, describing the use of fake document portals, CAPTCHA stages, cloned login pages, and multiple phishing kits including EvilProxy, FlowerStorm/Storm-1167, and Kali365. The report also highlighted infrastructure patterns such as aged compromised domains, RDGA-style domains, and injected PHP content on dormant websites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.