Also known as: tracked as, Eagle Werewolf, Void Blizzard, Laundry Bear, UNC1549, Smoke Sandstorm, Nimbus Manticore, validation data, also NAC, BLUERABBIT
A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026.
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
49
Tools
0
Campaigns
103
IOCs
0
Observed Data
1
Tactics