A Nigerian-linked threat actor ran at least 10 phishing campaigns from infrastructure associated with zoom4usinvite[.]space and a cPanel account at vistejet[.]com, impersonating brands including the U.S. Social Security Administration, Zoom, Adobe, Google, Microsoft, Xfinity, VistaJet, and Paperless Post. The operation used adversary-in-the-middle phishing kits to steal credentials, payment-card and Social Security numbers, and real-time MFA codes, with Telegram bots supporting immediate credential collection and session control. Researchers linked kit development artifacts to the handle @xforgex and cited Nigerian mobile-provider allowlisting and Lagos MTN development-log access as evidence of the operator's origin.
One SSA-themed email campaign used Information@allsecured[.]net and a shortened t[.]co URL to direct victims to a fake SSA download site at icci-sa[.]com, where they received ScreenConnect.ClientSetup.exe. The customized ScreenConnect installer communicated with 15.204.43[.]235 over TCP/443 using encrypted ScreenConnect traffic, providing the operator potential remote-access backdoor capability. The broader infrastructure also distributed ScreenConnect and FleetDeck remote-management agents through BAT, HTA, MSI, and EXE payloads, combining financial-data theft and account takeover with persistent endpoint access.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Overview Matrix flagged zoom4usinvite[.]space as a Zoom-themed phishing site. Analysis of its open directory and a publicly readable 42 MB backup archive exposed additional phishing kits; related vistejet[.]com infrastructure expanded the observed operation to at least ten campaigns and was assessed as controlled by the same Nigerian-origin actor.
A phishing email impersonating the U.S. Social Security Administration used a t.co link to a fake SSA-themed site at icci-sa[.]com, where victims could download ScreenConnect.ClientSetup.exe. The customized installer subsequently communicated with 15.204.43[.]235 over encrypted TCP/443 ScreenConnect traffic.
Development logs on the actor-controlled infrastructure recorded 57 accesses from Lagos, Nigeria MTN egress ranges. The report treats these records, together with Nigerian mobile-provider allowlisting, as evidence of a Nigerian-origin operator.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 54 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
carlesi.vg
Open sourcemalware-traffic-analysis.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.