hacker-news · Crawled Jul 13, 2026
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
12 IoCs 1 Malware
Read original article ↗
AI Summary
A misconfigured server exposed three active Evilginx phishing operations targeting Microsoft 365 users, enabling attackers to bypass MFA through proxy-based login interception and abuse of Microsoft's legitimate device code flow. The operations, attributed to threat actors codemado, mail-argenta, and saroula01, leveraged custom forks of open-source Evilginx hosted on public GitHub repositories. One campaign used AI-assisted development, and all three harvested corporate credentials, with sessions maintained via long-lived cookies and token refresh mechanisms. The incident highlights the growing accessibility of phishing-as-a-service and the need for robust Conditional Access policies.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 12 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 185[.]163[.]204[.]7 | Details → |
| Domain | picis[.]net | Details → |
| Domain | romnor[.]ca | Details → |
| Filename | evilginx2.exe | Details → |
| Filename | C:\Program Files (x86)\XEOX\xeox-agent_x64.exe | Details → |
| GitHub Repo | codemado/Evilginx | Details → |
| GitHub Repo | mail-argenta/red-queen | Details → |
| GitHub Repo | saroula01/black-queen | Details → |
| GitHub User | codemado | Details → |
| GitHub User | mail-argenta | Details → |
| GitHub User | saroula01 | Details → |
| Registry User | RockyBelling | Details → |