Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators

ws01.xeox.com

TLP:CLEAR
Active

Domain

Description

A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through M...

Sightings (0)

No sightings recorded yet

Details

Name / Label
One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators
Pattern Type
STIX
Confidence
75%
Valid From
Jul 13, 2026 10:50
Total Sightings
0
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of ws01.xeox.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.