Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors codemado

Also known as: tracked as, Eagle Werewolf, Void Blizzard, Laundry Bear, UNC1549, Smoke Sandstorm, Nimbus Manticore, validation data, also NAC, BLUERABBIT

Description

A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026.

Goals & Targeting

Targeted Sectors

Financial services
Government
Healthcare
Construction
Retail
Defense
Hospitality
Media
Aerospace
Oil gas

Targeted Countries / Regions

United States of America
Australia
Brazil
Canada
France
Norway
Poland
Singapore
Slovenia
Spain
Switzerland
United Kingdom of Great Britain and Northern Ireland

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Initial Access
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.microsoft.com — Cited by web research for: ScreenConnect
  2. www.microsoft.com — Cited by web research for: Microsoft Teams
  3. www.joesandbox.com — Cited by web research for: CALENDAR

Intel Summary

1

Techniques

49

Tools

0

Campaigns

103

IOCs

0

Observed Data

1

Tactics

Tags

Phishing

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
Jul 13, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.