Home » Emerging Technologies » Cyber Security » AiTM Phishing Campaign Targets Global Institutions
News Desk -

Share

AiTM phishing is at the center of a newly uncovered cyber campaign targeting universities, enterprises, and multinational institutions, including agencies of the European Union and the United Nations. The findings come from Infoblox Threat Intel, which revealed a sophisticated adversary-in-the-middle (AiTM) operation designed to steal credentials and authenticated session tokens in real time.

According to Infoblox Threat Intel, the campaign relies on procurement-themed emails sent from previously compromised organizational accounts. Because the emails originate from trusted sources, they appear legitimate and are more likely to deceive recipients.

After users click the malicious links, the attackers intercept credentials and authenticated session tokens, including those protected by multi-factor authentication (MFA). As a result, the attackers can bypass many of the identity security controls organizations depend on to protect user accounts.

For victims, the attack often appears to be part of a normal workday. The emails may contain bid invitations, shared project files, or requests for information. They also use false deadlines and confidentiality language to create urgency. Meanwhile, familiar-looking login pages and document portals make the process appear authentic.

However, behind the scenes, the attackers use adversary-in-the-middle infrastructure to capture authentication data as users sign in. This enables them to gain unauthorized access to organizational accounts and networks.

The research also found that the threat actor rotates between multiple phishing-as-a-service kits, including EvilProxy, FlowerStorm, and Kali365. At the same time, the campaign uses compromised, often dormant, websites to host nearly identical fake download pages. Although these websites may appear more trustworthy than newly registered malicious domains, defenders can still identify the campaign through recurring infrastructure patterns, reused resources, and suspicious subdomain conventions.

“These actors are using trust in organizational processes, like purchases, to convince people to hand over their credentials,” said Dr. Renée Burton, Vice President of Infoblox Threat Intel. “It’s not a phishing scenario that you are usually warned about in security training.”

The findings highlight the importance of combining user awareness with stronger identity protection and early threat detection. In particular, AiTM phishing campaigns demonstrate how trusted business workflows can be exploited to compromise organizations despite MFA protections.

Infoblox said DNS-based threat intelligence can help security teams detect phishing infrastructure before users reach fraudulent websites or attackers obtain authenticated sessions. The company added that AiTM phishing detection should be part of a broader cybersecurity strategy to identify campaign patterns early and reduce organizational risk.