Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators

0
Medium
Published: 07/13/2026 (07/13/2026, 10:36:53 UTC)
Source: AlienVault OTX General

Description

A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 12:42:26 UTC

Technical Analysis

The threat involves a misconfigured Python HTTP server that publicly exposed the complete infrastructure of three phishing operators running AiTM (Adversary-in-the-Middle) phishing campaigns. The operators—codemado (Egyptian, active since 2018), saroula01, and mail-argenta (Nigerian)—leveraged customized Evilginx forks and AI-assisted development to bypass MFA protections, primarily targeting Microsoft 365 accounts. The exposed server contained detailed operational data including phishing site configurations, credential logs, remote management tool installers, combolists, and Telegram session files. Saroula01's OAuth Device Code Flow attacks resulted in 218 victims across 12 countries over a year. Codemado is linked to the RockyBelling cybercrime ecosystem. The exposure reveals sustained phishing operations from early 2025 through mid-2026.

Potential Impact

The exposure of the full phishing infrastructure allows defenders and law enforcement to analyze and potentially disrupt three active AiTM phishing campaigns. The operators targeted Microsoft 365 accounts with MFA bypass techniques, increasing the risk of credential theft and account compromise. The leak of credential logs and remote management tool installers indicates potential for widespread account takeovers and persistence. The campaigns affected victims in multiple countries, with at least 218 confirmed victims from saroula01's OAuth abuse. This exposure undermines the operators' ability to continue stealthy operations and may lead to takedowns or mitigations.

Defensive Guidance

This threat results from a misconfiguration on the attackers' server rather than a vulnerability in legitimate software. There is no patch or fix applicable to defenders. Organizations should ensure robust MFA implementations and monitor for signs of AiTM phishing attacks, particularly targeting Microsoft 365 accounts. Awareness of OAuth Device Code Flow abuse and customized Evilginx phishing frameworks can aid detection. Since the exposed infrastructure is now public, defenders can use the leaked indicators and configurations to improve detection and response. No direct remediation is available for the exposed server itself.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://blog.lexfo.fr/opendir-to-phishing-operator.html"]
Adversary
codemado
Pulse Id
6a54bfc57c70fae743cb883e
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainpicis.net
domainhrvetbr.picis.net
domainhervw.picis.net
domaincdn.picis.net
domainhervw2.picis.net
domainewfweo.picis.net
domainhtejre.picis.net
domainsso.picis.net
domainjrhte.picis.net
domainevents.api.picis.net
domainmejeff.picis.net
domainhvr34gr.picis.net
domainimg1.picis.net
domainqueeenspropertyservices.ca
domainromnor.ca
domainsimple.run
domainaccount.picis.net
domainaccount.romnor.ca
domainaccounts.picis.net
domainagent01.xeox.com
domainb8c4u.picis.net
domainbilling.picis.net
domainbriefing.romnor.ca
domainc9x3h.picis.net
domaindownload.romnor.ca
domaine2a6m.picis.net
domainf3d9v.picis.net
domaing7k1w.picis.net
domaingui.picis.net
domainh6y2s.picis.net
domainhcwdg.picis.net
domainhnrvrve.picis.net
domainhterw.picis.net
domainimg6.picis.net
domaink9m2x.picis.net
domainl5p0n.picis.net
domainouti.picis.net
domainowa.picis.net
domainportal.xeox.com
domainq4b7j.picis.net
domainroweri.picis.net
domainsecure.picis.net
domainshare.romnor.ca
domainsign.romnor.ca
domaint5z1r.picis.net
domainteam.romnor.ca
domaintrack.picis.net
domainv3n8p.picis.net
domainverify.picis.net
domainvinicious.picis.net
domainw4j1q.picis.net
domainws01.xeox.com

Ip

ValueDescriptionCopy
ip83.136.211.85
ip188.227.196.240
ip216.180.245.166

Hash

ValueDescriptionCopy
hash1a37b674ed29c877890834e9aba616d9
hashea5d2096a2ef3dfe4fb870bd1f0270efaea993a6
hash7f30259d72eb7432b2454c07be83365ecfa835188185b35b30d11654aadf86a0
hash2ea61cdead470f570586f513e22d43d787befec6
hash35f23dfb4135d4cd38a6a29e64d79191d166344d
hash6a4cb1c75e1c59bbd4fbc4667f4c3bb5a74fe965
hashcf3cbf93adf43d50618c88705857d3adb123ed24
hashe9a44b3fe951cca57313533d6bc1d11e789c2018
hasheb8ede7598220dbef28953dc7df2e5418d52fa36
hashf496736e2d2344de7963d4f722381f03227ec452

Cidr

ValueDescriptionCopy
cidr80.80.250.0/24

Url

ValueDescriptionCopy
urlhttp://account.romnor.ca/go
urlhttp://briefing.romnor.ca/go
urlhttp://download.romnor.ca/go
urlhttp://share.romnor.ca/go
urlhttp://sign.romnor.ca/go
urlhttp://team.romnor.ca/go
urlhttp://verify.picis.net/verify-human

Threat ID: 6a54c5e868715ace43c4fa76

Added to database: 07/13/2026, 11:03:04 UTC

Last enriched: 08/12/2026, 12:42:26 UTC

Last updated: 08/26/2026, 14:48:57 UTC

Views: 330

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses