Authors: Darby Wise, Nick Sundvall
Executive Summary
Right now, someone may be sitting invisibly between your users and their login pages. They’re not guessing passwords. They’re not cracking MFA codes. They’re simply waiting, and when the authentication succeeds, they take the session. This is adversary-in-the-middle phishing (AiTM), and it has quietly become one of the most effective techniques in the modern threat actor’s toolkit. The campaign we will detail here targets universities, enterprises, and multinational institutions, including European Union and United Nations agencies. The actor routes attacks through seemingly compromised small-business sites and turns trusted infrastructure into cover. The goal is no longer access: it’s authenticated trust.

In May 2026, a contact shared an email they received related to a security event they were working to understand. What started as a phishing email to a small group of employees had snowballed. Once those accounts were compromised, the actor used them to distribute their lures more broadly across the organization. Using the email they shared with us, we were able to uncover a sophisticated AiTM phishing campaign targeting dozens of organizations with project-themed lures.
This is not an isolated trend. Last December, we documented a separate AiTM actor targeting U.S. university SSO portals using Evilginx. Where that actor relied on freshly registered phishing domains, this one uses aged, often dormant domains that are likely compromised and injected with a PHP file to host fake file download sites.
By inserting themselves directly into legitimate sign-in workflows, attackers can capture session cookies, authentication tokens, and multi-factor authentication (MFA)-protected access in real time, allowing them to bypass many of the controls organizations rely on to secure their identities. The takeaway: stronger authentication alone isn’t enough when attackers can hijack the session itself.
The campaigns described in this blog appear to be the work of a single actor who leverages multiple AiTM phishing kits, including Evilginx, FlowerStorm, and Kali365, to harvest user credentials. The use of procurement lures and emails sent from previously compromised accounts indicates that they are targeting businesses rather than individuals. The attack chain includes brand impersonation of well-known contract platforms and perfectly replicated login portals for the targets. The goal is to collect credentials for high value networks rather than grandpa’s credit card.
Campaign Analysis
Phishing Emails
This campaign begins with emails sent from compromised organizational accounts, a tactic used to lend credibility to the lures. The emails themselves are themed around professional workflows: requests for information (RFIs), formal bid invitations, and shared project documentation. Examples of select phishing lures are shown below in Figure 1. These emails also feature common social engineering elements, including fake deadlines that pressure recipients to act quickly, and confidentiality language that discourages them from sharing the email or seeking a second opinion.


Figure 1. Redacted screenshot of sample phishing emails sent to targeted victims through compromised Microsoft Outlook accounts
We don’t have information about how the accounts of the small group of initial recipients were initially compromised, but it is common for threat actors to rapidly weaponize such accounts to distribute identical lures to internal and external contacts as they did in this case. They transformed trusted mailboxes into force multipliers for further compromise. The combination of legitimate infrastructure abuse, institutional brand impersonation, and social engineering reflects a mature and scalable operation designed to undermine trust.
Impersonated Login Portals
Once victims click on the link in the phishing email, they are sent through a carefully engineered sequence of fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating trusted services including Microsoft, OpenGov, and European financial institutions. The spoofed portals and pages aim to build user trust while obscuring the underlying phishing infrastructure. Rather than directing victims immediately to a credential harvesting page, the actor introduces several intermediate steps that mimic legitimate download workflows and verification processes.
Victims who click the links embedded in the phishing emails are first directed to the websites hosting the fake document download pages as seen in Figure 2 below. In many cases, the victim’s email address is embedded directly in the URL path (e.g., /user@company[.]com/), reinforcing the illusion that the content is intended specifically for them.

Figure 2. Screenshot of a fake download page impersonating ConstructConnect
When the victim attempts to download the files, the page presents a prompt requiring their email address to continue. To enhance legitimacy, these prompts feature branding for popular government and construction operations platforms such as OpenGov and ConstructConnect. Once the victim enters a valid email, they are redirected to either a legitimate Cloudflare Turnstile or a generic CAPTCHA instance hosted on actor-controlled domains. These domains are likely generated by a registered domain generation algorithm (RDGA); the domains associated with EvilProxy and FlowerStorm/Storm-1167 phishing kits follow the RDGA patterns in Table 1. Phishing pages using the FlowerStorm kit are hosted on subdomains of the RDGA domains; some subdomains are random English words or strings, while others follow company branding themes (e.g. ajgroupuae[.]usersatisfactionlab[.]de).
In some cases, the actor-controlled phishing page is conditionally cloaked: users who provide non-targeted email addresses during the prompt step may be redirected to a benign decoy page. In one test, we were redirected to the legitimate page for Houzz, a home design and renovation platform, after entering a fake email address in a prompt that was impersonating ConstructConnect.
| Phishing Kit | RDGA Pattern | Sample Domains |
|---|---|---|
| FlowerStorm/Storm-1167 | <two to four corporate buzzwords>.de | usersatisfactionlab[.]de sustainablegrowthlaunch[.]de solidhostingservices[.]de reliablecontinuitysolutions[.]de innovativegrowthstrategy[.]de designenhancessatisfaction[.]de |
| EvilProxy | <two to four corporate buzzwords>.<net or com> | q1evaluationperformance[.]net corporatetermscompliance[.]com assessmentevaluationreport[.]com |
Table 1. RDGA domain patterns for phishing pages
Once the victim completes the CAPTCHA, they are directed to a fake Microsoft authentication page; some of these pages also feature branding elements associated with the targeted organization. Figure 3 shows an example of a page impersonating the European Investment Bank.

Figure 3. Redacted screenshot of a fake authentication page impersonating the European Investment Bank
Beware the Invisible Actor
These login pages aren’t just forms in a simple phishing campaign: they are components of an AiTM phishing framework. The actor rotates between multiple AiTM kits—including EvilProxy and FlowerStorm/Storm-1167—to intercept MFA-protected sessions in real time and maintain operational resilience. When a user enters their credentials and completes MFA, the information is relayed in real time to the legitimate authentication service, while session tokens and cookies are intercepted by the attacker. This allows the operator to establish authenticated sessions without needing to directly bypass MFA protections.
All stages of this campaign mirror legitimate download and authentication workflows to build user trust. By taking the victims through several seemingly legitimate interactions (file access, email verification, CAPTCHA completion, login) the actor reduces the likelihood that any single step will trigger suspicion or detection.
Phishing Kits
Analysis of the campaign infrastructure indicates that the actor rotates between multiple AiTM phishing-as-a-service (PhaaS) platforms rather than relying on a single phishing framework. Table 2 shows information about the kits we’ve observed the threat actor using as part of this campaign, although they’ve likely used other kits as well.
| Kit | First Seen | Core Technique | Target Victims | Threat Actor Usage |
|---|---|---|---|---|
| EvilProxy | 2022 | Reverse proxy | Credentials for a variety of services across many sectors | Broad PhaaS use; enables low-skill actors |
| FlowerStorm | June 2024 | Reverse proxy | Microsoft 365 credentials mainly in professional services, finance, legal, manufacturing sectors | Likely a rebrand of Rockstar2FA after its disruption in 2024 |
| Kali365 | April 2026 | Device code abuse + AiTM session capture | Microsoft 365 credentials across many sectors | Tiered reseller and affiliate model; low technical barrier |
Table 2. AiTM phishing kits observed in this campaign
Fake Document Download Sites
Several phishing emails we were able to analyze contained a link to testserveren[.]com, a domain hosting a page designed to mimic a legitimate file-sharing platform, as shown in Figure 4, which presents the victim with what appears to be four shared files available for download; filenames are carefully chosen to match those referenced in the original lure email. Downloading these files will redirect the victim to a phishing site rather than delivering the content they expect.

Figure 4. Fake UN file download page
A different URL on testserveren[.]com hosted a similar page impersonating OpenGov, a procurement and contract management company used by state and local governments in the United States. See Figure 5.

Figure 5. Email prompt impersonating OpenGov
Notably, testserveren[.]com appears to have sat completely dormant for nearly a decade, with no trace of the site serving anything at all before May 2026. While registration data is private, there are no obvious indicators of a change in ownership around the time the malicious activity began.
It was a similar story for another domain, barifurniture[.]net, which was registered in 2015 and did not show signs of malicious activity until May 2026. The domain name implies that it is a furniture company, and historically the content of the domain pertained to selling furniture. Yet as Figure 6 shows, this fake download page is branded as “NUS Consulting Group.”

Figure 6. Fake NUS Consulting Group file download page
Our investigation identified dozens of additional domains hosting near-identical content, consistent with the use of a shared phishing kit. The domains in this cluster share several characteristics that point toward compromise rather than fresh registration: the average domain age exceeds six years, registration and hosting details vary across the cluster, and the domains appear to have been registered at seemingly unrelated times. On top of that, the sites appear to inject an index.php file that loads the malicious content. Taken together, these traits suggest the actor may have compromised aged domains to lend credibility to the campaign and evade detection.
Security Implications and Conclusion
Our research into this AiTM phishing actor reflects a broader evolution in phishing operations. Attackers are no longer focused solely on stealing credentials, but also on stealing trusted, authenticated sessions to gain unauthorized access to user accounts. Phishing campaigns are becoming infrastructure-aware, identity-centric, and increasingly optimized to exploit user trust rather than technical vulnerabilities. By creating a framework out of compromised (aged) legitimate domains, multiple AiTM frameworks, and carefully staged user interactions, the actor behind these attacks demonstrates a mature understanding of modern identity defenses and how to circumvent them.
As AiTM tooling becomes more accessible and legitimate websites continue to be repurposed as attack infrastructure, organizations can no longer view MFA as a standalone defense. When authentication flows are proxied in real time, attackers can capture and reuse session tokens, effectively inheriting the victim’s authenticated identity. As organizations continue to adopt cloud-first architectures and identity-centric security models, the compromise of a trusted, MFA-validated session carries the same risk as a compromised password—without triggering the controls built to catch one. Understanding how modern phishing operations bypass identity protections is becoming essential for defending enterprise environments at scale.
As AiTM tooling matures and compromised legitimate infrastructure increasingly proves to be an effective delivery mechanism, detection approaches that rely solely on domain reputation, URL analysis, or content inspection may prove to be ineffective. What persists is DNS. The domains underpinning these campaigns leave fingerprints: RDGA patterns, subdomain conventions, and infrastructure reuse that remain visible to passive DNS analysis long after individual phishing URLs have expired. DNS-based threat intelligence offers a detection layer that operates upstream of authentication, before the user enters credentials or clicks through a CAPTCHA gate, and before the attacker walks away with a stolen session token.
Indicators
The table below provides a curated selection of indicators related to the threats discussed. A more comprehensive list of indicators can be found in our GitHub repository.
| Indicator | Description |
|---|---|
| barifurniture[.]net satoriestate[.]com sohantraders[.]com testserveren[.]com vresortsliving[.]com |
Domains likely compromised and hosting fake document download pages |
| consistenthostinghub[.]de designenhancessatisfaction[.]de evergreenhostingoptions[.]de innovativegrowthstrategy[.]de reliablecontinuitysolutions[.]de sustainablegrowthlaunch[.]de solidhostingservices[.]de usersatisfactionlab[.]de |
FlowerStorm/Storm-1167 Domains |
| assessmentevaluationreport[.]com corporatetermscompliance[.]com employeehandbookcompliance[.]com esignidentification[.]com q1evaluationperformance[.]net |
EvilProxy PhaaS Domains |
| duemineral[.]uk | Kali365 PhaaS Domain |

