hacker-news · Crawled Jul 13, 2026

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

12 IoCs 1 Malware
Read original article ↗

AI Summary

A misconfigured server exposed three active Evilginx phishing operations targeting Microsoft 365 users, enabling attackers to bypass MFA through proxy-based login interception and abuse of Microsoft's legitimate device code flow. The operations, attributed to threat actors codemado, mail-argenta, and saroula01, leveraged custom forks of open-source Evilginx hosted on public GitHub repositories. One campaign used AI-assisted development, and all three harvested corporate credentials, with sessions maintained via long-lived cookies and token refresh mechanisms. The incident highlights the growing accessibility of phishing-as-a-service and the need for robust Conditional Access policies.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 12 extracted

Type Value Detail
IP 185[.]163[.]204[.]7 Details →
Domain picis[.]net Details →
Domain romnor[.]ca Details →
Filename evilginx2.exe Details →
Filename C:\Program Files (x86)\XEOX\xeox-agent_x64.exe Details →
GitHub Repo codemado/Evilginx Details →
GitHub Repo mail-argenta/red-queen Details →
GitHub Repo saroula01/black-queen Details →
GitHub User codemado Details →
GitHub User mail-argenta Details →
GitHub User saroula01 Details →
Registry User RockyBelling Details →

MITRE ATT&CK TTPs 7 techniques