A sophisticated phishing campaign is using procurement-themed emails and adversary-in-the-middle (AiTM) kits to steal MFA-protected Microsoft 365 sessions.
Rather than breaking MFA, attackers proxy legitimate sign-in flows and capture the session cookies and tokens created after victims authenticate.
The campaign reportedly targets enterprises, universities, multinational organizations, and public-sector entities through RFIs, bid invitations, and project-document lures.
Attackers send messages from previously compromised organizational mailboxes, making the email appear more credible and enabling further internal and external phishing distribution
Victims are routed through fake file-sharing pages impersonating services such as OpenGov, ConstructConnect, and United Nations-related platforms.
The pages may include personalized email-address paths, file-download prompts, CAPTCHA checks, and urgency-based language intended to make the workflow look legitimate.

Researchers observed malicious download portals on likely compromised, aged domains including testserveren[.]com, barifurniture[.]net, satoriestate[.]com, sohantraders[.]com, and vresortsliving[.]com.
The use of dormant domains instead of newly registered phishing sites can help attackers evade reputation-based blocking.
AiTM Kits Hijack Microsoft 365
After a victim passes the staged download and CAPTCHA process, the campaign presents a cloned Microsoft 365 sign-in page, sometimes branded for the targeted organization.
The AiTM server relays credentials and MFA interactions to the real Microsoft authentication service in real time, then intercepts the authenticated browser session.
The actor has been linked to multiple phishing-as-a-service tools, including EvilProxy, FlowerStorm/Storm-1167, and Kali365. EvilProxy uses reverse-proxy architecture to collect credentials, cookies, and authentication tokens.
At the same time, FlowerStorm is also designed to target Microsoft 365 users and bypass MFA through AiTM techniques.

Observed FlowerStorm-related domains follow recurring RDGA-style naming patterns, often combining corporate-sounding terms unde
Stolen session tokens can give an attacker authenticated access to a mailbox or cloud account without repeatedly requesting the victim’s password or MFA code. This access can support business email compromise, internal phishing, data theft, and lateral movement.
Organizations should treat unexpected procurement emails, document-sharing links, and CAPTCHA-gated sign-in prompts as high-risk especially when a login page appears after clicking an unsolicited document link.
Phishing-resistant authentication, conditional-access controls, session monitoring, DNS intelligence, and rapid token revocation can reduce exposure to these attacks. techcommunity, infoblox said.
Indicators of Compromise
| Indicator Type | IOC | Description |
|---|---|---|
| Compromised hosting domain | barifurniture[.]net | Hosted fake NUS Consulting Group document-download content |
| Compromised hosting domain | satoriestate[.]com | Likely compromised domain used for fake document portals |
| Compromised hosting domain | sohantraders[.]com | Likely compromised domain used for phishing delivery |
| Compromised hosting domain | testserveren[.]com | Hosted fake UN and OpenGov file-sharing pages |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.