Breaking Down the Misconfigured Server: A Deep Dive into Microsoft 365 Phishing Operations (2026)

In the world of cybersecurity, the battle against phishing attacks is an ongoing and complex challenge. A recent discovery by French security firm Lexfo has shed light on a sophisticated operation involving a misconfigured server, revealing three Evilginx phishing campaigns targeting Microsoft 365 users. This incident highlights the evolving tactics employed by attackers and the importance of staying vigilant in the face of emerging threats.

The story begins with a simple yet crucial detail: a misconfigured server left a Python web server running on a public port with directory listing enabled. This oversight inadvertently exposed a treasure trove of sensitive information, including phishing configurations, credential-harvesting logs, and even the operator's Telegram session files. It was a goldmine of data for cybersecurity researchers.

Lexfo's investigation led them to an Egyptian actor known as codemado, who has been active in VoIP and hacking forums since 2018. The firm uncovered a complex network of interconnected phishing campaigns, each utilizing a custom fork of the open-source Evilginx proxy, cloned from public GitHub repositories. These forks, named red-queen and black-queen, showcased the attackers' ingenuity and adaptability.

The red-queen fork, developed by a Nigerian operator called mail-argenta, demonstrated a high level of polish and sophistication. It employed URL-rewriting techniques to evade detection and pre-filled victim email addresses to reduce abandonment. The fork also set a one-year TTL on captured Microsoft session cookies, allowing it to outlast password resets and bypass Conditional Access policies. This fork was part of a larger ecosystem, as Lexfo also identified a phishing-as-a-service platform called The Quarry, run by a developer known as RockyBelling.

The black-queen fork, created by an anonymous author using the handle saroula01, took a different approach. It leveraged Microsoft's OAuth device code flow, a legitimate sign-in path for input-constrained devices. By generating a real device code and presenting it on a lure page, the attacker could trick victims into clearing their MFA on genuine Microsoft infrastructure. This technique, while clever, does not bypass MFA; instead, it exploits the legitimate flow to gain access.

The report also highlighted the use of AI-assisted development in these phishing campaigns. Lexfo's CTI team noted signs of AI involvement, particularly in the glue code and scripts surrounding the Evilginx forks. However, the team emphasized that the framework itself was not heavily AI-driven, but rather the code built around it.

From a defensive perspective, the article emphasizes the importance of implementing phishing-resistant MFA, FIDO2, or passkeys. These measures can effectively shut down the Evilginx side of the attack by binding the sign-in to the real domain. However, the report also underscores the need for Conditional Access policies to address device-code abuse. By blocking the device code flow and continuously evaluating access, organizations can mitigate the risk of stolen tokens being used.

In conclusion, this incident serves as a stark reminder of the ever-evolving nature of phishing attacks and the need for proactive defense strategies. As attackers continue to innovate and adapt, it is crucial for organizations to stay informed, implement robust security measures, and collaborate with cybersecurity experts to stay one step ahead in the ongoing battle against phishing threats.

Breaking Down the Misconfigured Server: A Deep Dive into Microsoft 365 Phishing Operations (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 5931

Rating: 4.2 / 5 (63 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.