The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions
An adversary-in-the-middle (AiTM) phishing campaign is targeting global institutions including EU and UN agencies using procurement-themed lures sent from compromised organizational email accounts. The actor rotates between multiple AiTM phishing kits (EvilProxy, FlowerStorm/Storm-1167, Kali365) and uses aged, likely compromised domains injected with PHP to host fake document download portals. By proxying authentication flows in real time, the attacker captures session tokens and cookies after MFA completion, bypassing identity controls and inheriting the victim's authenticated session.
- domainassessmentevaluationreport[.]comEvilProxy PhaaS RDGA domain following <corporate buzzwords>.com pattern used for AiTM phishing
- domainbarifurniture[.]netAged domain (registered 2015, dormant until May 2026) compromised to host fake NUS Consulting Group file download page
- domainconsistenthostinghub[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domaincorporatetermscompliance[.]comEvilProxy PhaaS RDGA domain following <corporate buzzwords>.com pattern
- domaindesignenhancessatisfaction[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domainduemineral[.]ukKali365 PhaaS domain used for AiTM session capture targeting Microsoft 365 credentials
- domainemployeehandbookcompliance[.]comEvilProxy PhaaS RDGA domain following <corporate buzzwords>.com pattern
- domainesignidentification[.]comEvilProxy PhaaS RDGA domain following <corporate buzzwords>.com pattern
- domainevergreenhostingoptions[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domaininnovativegrowthstrategy[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domainq1evaluationperformance[.]netEvilProxy PhaaS RDGA domain following <corporate buzzwords>.net pattern used for AiTM phishing
- domainreliablecontinuitysolutions[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domainsatoriestate[.]comDomain likely compromised, hosting fake document download pages as part of the campaign
- domainsohantraders[.]comDomain likely compromised, hosting fake document download pages as part of the campaign
- domainsolidhostingservices[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domainsustainablegrowthlaunch[.]deFlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de pattern
- domaintestserveren[.]comAged domain (dormant ~10 years) compromised and injected with PHP to host fake document download pages impersonating UN procurement and OpenGov portals
- domainusersatisfactionlab[.]deFlowerStorm/Storm-1167 RDGA domain used to host phishing pages; subdomains (e.g. ajgroupuae.usersatisfactionlab.de) host cloned Microsoft authentication pages
- domainvresortsliving[.]comDomain likely compromised, hosting fake document download pages as part of the campaign
Detection / Hunteropenrouter
What Happened
A sophisticated phishing campaign is targeting large organizations, including universities and international agencies like the United Nations, by impersonating procurement and contract management platforms. The attackers send professional-looking emails about bidding opportunities from already-compromised email accounts, making the messages appear trustworthy. When recipients click the links, they are taken through a series of convincing fake websites that ultimately capture their login credentials and authentication sessions — even when multi-factor authentication (MFA) is enabled. The attackers use a technique called adversary-in-the-middle (AiTM), where they sit invisibly between the user and the real login service, intercepting the session after authentication succeeds. Organizations should be aware that MFA alone does not protect against this type of attack, and should consider additional layers of defense such as DNS-based threat intelligence, session monitoring, and employee awareness training focused on procurement-themed phishing lures.
Key Takeaways
- AiTM phishing campaign targets universities, enterprises, and multinational institutions including EU and UN agencies using procurement-themed lures (RFIs, bid invitations, project documentation)
- Actor rotates between multiple AiTM phishing kits — EvilProxy, FlowerStorm/Storm-1167, and Kali365 — to intercept MFA-protected sessions in real time and steal session tokens
- Campaign uses aged, likely compromised domains (dormant for 6+ years) injected with PHP files to host fake document download portals, evading domain-reputation-based detection
- Phishing kit domains follow registered domain generation algorithm (RDGA) patterns: FlowerStorm uses .de TLD with corporate buzzwords; EvilProxy uses .net/.com TLDs
- Emails originate from previously compromised organizational Microsoft Outlook accounts, turning trusted mailboxes into force multipliers for lateral phishing spread
Affected Systems
- Microsoft 365 / Azure AD SSO portals
- Microsoft Outlook (compromised accounts used for phishing distribution)
- Organizational email systems at universities, enterprises, EU agencies, and UN agencies
- Web servers running PHP (compromised aged domains injected with malicious index.php)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Compromised organizational Microsoft Outlook accounts send procurement-themed phishing emails (RFIs, bid invitations, project documentation) to internal and external contacts
- Redirection: Victims click links directing to compromised aged domains hosting fake document download portals impersonating brands like ConstructConnect, OpenGov, and UN procurement
- Credential Collection: Fake portal prompts victim for email address, then redirects to CAPTCHA verification (Cloudflare Turnstile or actor-controlled generic CAPTCHA) on RDGA-generated domains
- AiTM Session Capture: Victim directed to cloned Microsoft authentication page where AiTM reverse proxy intercepts credentials, MFA tokens, and session cookies in real time by relaying authentication to legitimate service
- Account Access: Attacker uses stolen session tokens to establish authenticated sessions without needing to bypass MFA, inheriting victim's authenticated identity
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Infoblox GitHub repository (referenced but not included in article)
The article references a more comprehensive list of indicators available in the Infoblox GitHub repository, but no detection rules (YARA, Sigma, Snort/Suricata, KQL, SPL, EQL) are provided in the blog post itself. DNS-based threat intelligence is highlighted as the primary detection approach.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | This is primarily a phishing and session hijacking campaign that operates through web browsers. EDR telemetry would not capture the AiTM proxy interception or session token theft, as these occur within the browser's HTTPS session. EDR may detect subsequent post-compromise activity if the attacker uses stolen sessions for lateral movement. |
| Network Visibility | Medium | DNS queries to RDGA-pattern domains and compromised aged domains are visible at the network layer. Passive DNS analysis can identify infrastructure patterns. However, HTTPS traffic to phishing pages would require TLS inspection to see full URL paths and content. |
| Detection Difficulty | Hard | The campaign uses aged domains with good reputation, legitimate compromised email accounts for distribution, multi-stage redirection through CAPTCHA and fake portals, and conditional cloaking that redirects non-targeted users to benign pages. Traditional URL analysis and domain reputation checks are ineffective. DNS-based RDGA pattern detection and passive DNS analysis are the most promising approaches but require specialized tooling. |
Required Log Sources
- DNS query logs (passive DNS, recursive resolver logs)
- Web proxy logs with URL filtering
- Email gateway logs (for phishing email detection from compromised accounts)
- Microsoft 365 sign-in logs (for anomalous session activity)
- Azure AD conditional access logs
- Cloudflare Turnstile / CAPTCHA interaction logs if available
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for DNS queries to domains matching RDGA patterns — specifically .de domains composed of two to four concatenated corporate buzzwords (FlowerStorm) or .net/.com domains with similar patterns (EvilProxy). These may indicate users being redirected to AiTM phishing infrastructure. | DNS query logs, passive DNS data, recursive resolver logs | Initial Access / Redirection | Medium — legitimate domains may occasionally match buzzword concatenation patterns; correlate with other indicators such as recent domain activity changes or subdomain patterns |
| Consider hunting for email messages originating from organizational accounts that were recently flagged for compromise, containing procurement-themed language (RFI, bid invitation, project documentation) with embedded links to file download portals. | Email gateway logs, Microsoft 365 mail flow logs, DLP logs | Initial Access | Low to Medium — legitimate procurement emails exist, but the combination of recently compromised sender accounts and specific lure language patterns narrows the scope |
| Consider hunting for Microsoft 365 sign-in events where the session was established from an IP address or user-agent inconsistent with the user's typical pattern, particularly shortly after a phishing email was clicked. This may indicate a stolen session token being used by the attacker. | Azure AD sign-in logs, Microsoft 365 audit logs, conditional access logs | Account Access / Session Hijacking | Medium — legitimate users may travel or use new devices; correlate with preceding phishing email interaction and URL click events |
| Consider hunting for web traffic to domains that were dormant for multiple years and suddenly began serving content, particularly with index.php injection patterns. This may indicate compromised aged domains being weaponized. | DNS historical records, web proxy logs, passive DNS analysis, certificate transparency logs | Infrastructure Setup | Low — domains dormant for 6+ years that suddenly serve PHP content are unusual; however legitimate site revivals do occur |
| Consider hunting for subdomains of RDGA-pattern domains that follow company branding themes (e.g., <companyname>.<rdga-domain>), as these are used to host cloned authentication pages targeting specific organizations. | DNS query logs, passive DNS data, certificate transparency logs | Credential Harvesting | Low — branded subdomains on recently activated RDGA parent domains are highly suspicious |
Control Gaps
- Domain reputation-based URL filtering will not flag aged domains with long-standing clean reputation that have been recently compromised
- MFA enforcement does not prevent AiTM session token theft, as the attacker proxies the legitimate MFA flow and captures the resulting session cookie
- Content inspection of phishing pages may be evaded through conditional cloaking that redirects non-targeted email addresses to benign decoy pages
- Email authentication (SPF/DKIM/DMARC) will not block phishing emails sent from legitimately compromised organizational accounts
- Traditional phishing detection relying on freshly registered domain patterns will miss this campaign's use of aged domains
Key Behavioral Indicators
- DNS queries to .de domains matching pattern of 2-4 concatenated corporate buzzwords (FlowerStorm RDGA)
- DNS queries to .net/.com domains matching pattern of 2-4 concatenated corporate buzzwords (EvilProxy RDGA)
- Sudden web activity on domains with multi-year dormancy gaps in passive DNS history
- Subdomains of RDGA-pattern domains following targeted organization branding themes
- Victim email address embedded in URL path of phishing landing pages (e.g., /[email protected]/)
- Multi-stage redirect chain: document portal → email prompt → CAPTCHA → Microsoft login page on different domain
- Procurement-themed email lures (RFI, bid invitation, project documentation) from compromised internal accounts
False Positive Assessment
Medium — The RDGA domain patterns (concatenated corporate buzzwords) could occasionally match legitimate domain registrations. Procurement-themed emails are common in enterprise environments and not all are malicious. However, the combination of aged dormant domains suddenly serving PHP content, RDGA patterns, and multi-stage redirect chains significantly reduces false positive risk when correlated.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified compromised domains and RDGA-pattern domains at DNS resolver and web proxy levels.
- Consider reviewing Microsoft 365 sign-in logs for anomalous sessions originating from unexpected IP addresses or user-agents, particularly for users who may have received procurement-themed phishing emails.
- If your email security platform supports it, consider searching for procurement-themed phishing emails (RFIs, bid invitations, project documentation) sent from recently compromised organizational accounts, both internal and from partner organizations.
- Evaluate whether any of the listed domains have been accessed by users in your environment via DNS logs, proxy logs, or firewall logs.
Infrastructure Hardening
- Consider implementing DNS-based threat intelligence feeds that can detect RDGA patterns and flag domains with sudden activity after long dormancy periods.
- If supported by your identity provider, evaluate implementing conditional access policies that restrict sessions based on IP location, device compliance state, and user-agent consistency, rather than relying solely on MFA.
- Consider implementing session token binding or continuous session verification mechanisms if your identity platform supports them, to reduce the impact of stolen session tokens.
- Evaluate whether your web filtering solution can detect and block multi-stage redirect chains characteristic of AiTM phishing workflows.
User Protection
- Consider deploying browser-based anti-phishing extensions that can detect cloned login pages and AiTM proxy behavior.
- If applicable to your environment, consider implementing FIDO2 hardware security keys which are resistant to AiTM attacks, as the authentication ceremony is cryptographically bound to the legitimate origin.
- Evaluate whether your endpoint protection can detect and alert on browser session cookie exfiltration attempts.
Security Awareness
- Consider incorporating procurement-themed phishing scenarios into existing security awareness training programs, emphasizing that legitimate-looking bid invitations and RFI documents can be phishing lures.
- Consider reminding users to verify procurement-related emails through out-of-band channels, especially when they contain urgent deadlines or confidentiality language designed to discourage verification.
- Consider educating users that MFA does not provide complete protection against all phishing techniques, and that they should verify the URL and domain of any login page before entering credentials.
- If your organization uses procurement or contract management platforms, consider informing users about the specific risk of impersonation of these platforms in phishing campaigns.
MITRE ATT&CK Mapping
Initial Access
Stealth
Lateral Movement
Collection
Additional IOCs
- Domains:
satoriestate[.]com- Domain likely compromised, hosting fake document download pages as part of the campaignsohantraders[.]com- Domain likely compromised, hosting fake document download pages as part of the campaignvresortsliving[.]com- Domain likely compromised, hosting fake document download pages as part of the campaignconsistenthostinghub[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patterndesignenhancessatisfaction[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patternevergreenhostingoptions[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patterninnovativegrowthstrategy[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patternreliablecontinuitysolutions[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patternsustainablegrowthlaunch[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patternsolidhostingservices[.]de- FlowerStorm/Storm-1167 RDGA domain following <corporate buzzwords>.de patterncorporatetermscompliance[.]com- EvilProxy PhaaS RDGA domain following <corporate buzzwords>.com patternemployeehandbookcompliance[.]com- EvilProxy PhaaS RDGA domain following <corporate buzzwords>.com patternesignidentification[.]com- EvilProxy PhaaS RDGA domain following <corporate buzzwords>.com pattern
- File Paths:
index.php- PHP file injected into compromised aged domains to load malicious fake document download page content