55 views
2 hours ago

Infoblox uncovers global AiTM phishing campaign targeting EU and UN

Dr. Renée Burton, Vice President of Infoblox Threat Intel.
Dr. Renée Burton, Vice President of Infoblox Threat Intel.

Infoblox Threat Intel has uncovered a sophisticated adversary-in-the-middle (AiTM) phishing campaign. Attackers use procurement-themed emails to hijack authenticated sessions and bypass multi-factor authentication, targeting global organisations including the UN and EU agencies. The campaign leverages Phishing-as-a-Service kits and compromised websites to deceive users.

The interesting angle of this attack is procurement-themed emails sent from previously compromised organizational accounts which make the messages appear credible. After a recipient clicks, this adversary-in-the-middle infrastructure intercepts credentials and authenticated session tokens in real time – even multi-factor authentication ones. This allows the attackers to bypass many of the controls organizations rely on to secure their identities.

For the recipient, the attack can look like an ordinary part of the workday: a bid invitation, a shared project file or a request for information. False deadlines and confidentiality language create urgency, while familiar-looking screens make it seem as though victims are accessing a document or signing in as usual. Behind the scenes, the attacker is using that trusted process to gain access to the organization’s account and network.

The actor appears to rotate among multiple phishing-as-a-service kits, including EvilProxy, FlowerStorm and Kali365, while using compromised, often dormant websites to host near-identical fake download pages. Those sites may look more trustworthy than newly created malicious domains, but their patterns, subdomain conventions and reused infrastructure can still expose the campaign to defenders.

“These actors are using trust in organizational processes, like purchases, to convince people to hand over their credentials,” said Dr. Renée Burton, Vice President of Infoblox Threat Intel. “It’s not a phishing scenario that you are usually warned about in security training.”

The findings reinforce the need for organizations to pair user awareness and identity controls with early visibility into the infrastructure behind phishing operations. DNS-based threat intelligence can help defenders identify campaign patterns upstream, before users reach fraudulent pages or attackers gain access to authenticated sessions.

Leave a Reply

Latest from Blog

(L-R) Ehab Aljabri, Projects Manager, Fujairah Digital Government; Yousuf Alkaabi, Government Communication Manager, Fujairah Digital Government; Dr. Ahmed Hassan Almurshidi, Director of Fujairah Geographic Information System Center, and Sheikh Eng. Mohammed bin Hamad bin Saif Alsharqi, General Director of Fujairah Digital Government, met with Marwan Zeineddine, Managing Director, SAP UAE, and SAP executives at the launch of the SAP YPP initiative.
(L-R) Ehab Aljabri, Projects Manager, Fujairah Digital Government; Yousuf Alkaabi, Government Communication Manager, Fujairah Digital Government; Dr. Ahmed Hassan Almurshidi, Director of Fujairah Geographic Information System Center, and Sheikh Eng. Mohammed bin Hamad bin Saif Alsharqi, General Director of Fujairah Digital Government, met with Marwan Zeineddine, Managing Director, SAP UAE, and SAP executives at the launch of the SAP YPP initiative.

Don't Miss

Renée Burton, Vice President of Infoblox Threat Intel

When your internet’s “GPS” starts Lying: Infoblox threat Intel uncovers actor compromising routers

Imagine you’re on your way to a new restaurant: you input the
Dr. Renée Burton, Vice President of Infoblox Threat Intel

Parked Domains: The internet’s forgotten real estate turning into a major security threat

New research from Infoblox Threat Intel shows that parked domains – long

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy