Threat actors exploit trusted procurement workflows and adversary-in-the-middle techniques to steal credentials and bypass multi-factor authentication
Infoblox Threat Intel has uncovered a sophisticated phishing campaign targeting universities, enterprises, multinational organizations, and government-linked institutions, including agencies associated with the European Union and the United Nations. The campaign leverages fake procurement-related emails and adversary-in-the-middle (AiTM) techniques to steal credentials and authenticated user sessions.
According to Infoblox researchers, the attackers are using previously compromised organizational email accounts to distribute procurement-themed messages, making the emails appear legitimate and increasing the likelihood of user engagement. Recipients are lured with bid invitations, project documents, or requests for information that mimic routine business communications.
“These actors are using trust in organizational processes, like purchases, to convince people to hand over their credentials. It’s not a phishing scenario that you are usually warned about in security training.”
Dr. Renée Burton, Vice President, Infoblox Threat Intel
Once a victim clicks on a malicious link, they are redirected to fraudulent document portals hosted on compromised websites. The AiTM infrastructure then intercepts login credentials and authenticated session tokens in real time, allowing attackers to bypass traditional security measures, including multi-factor authentication (MFA), and gain unauthorized access to corporate accounts and networks.
Researchers found that the threat actors frequently rotate between several phishing-as-a-service platforms, including EvilProxy, FlowerStorm, and Kali365. The campaign also relies on compromised and often dormant websites to host nearly identical phishing pages, making detection more challenging for security teams.
The findings highlight a growing trend in which cybercriminals exploit trusted business processes rather than relying solely on traditional phishing tactics. By mimicking procurement workflows and creating urgency through confidentiality notices and deadlines, attackers increase the effectiveness of their social engineering efforts.
Infoblox emphasized that organizations should complement user awareness training and identity security controls with advanced threat intelligence and infrastructure monitoring. DNS-based threat intelligence can help identify malicious infrastructure and attack patterns early, enabling defenders to block threats before users reach phishing pages or attackers successfully hijack authenticated sessions.
The research underscores the evolving sophistication of phishing campaigns and the need for organizations to strengthen defenses against credential theft and session hijacking attacks that increasingly target high-value institutional environments.
