Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Inside a Global Procurement-Themed AiTM Phishing Campaign

company.com

TLP:CLEAR
Active

Domain

Description

A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Inside a Global Procurement-Themed AiTM Phishing Campaign
Pattern Type
STIX
Confidence
75%
Valid From
Jul 23, 2026 14:00
Total Sightings
0
Added
Jul 23, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of company.com

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.