Press ReleaseIdentity & AccessThreat Detection & Defense

Phishing Campaign Targets Global Institutions with Fake Procurement Emails

Infoblox Threat Intel uncovers an operation that uses trusted business workflows, compromised websites, and fake document portals to pursue high-value organisational access.

Right now, someone may be sitting invisibly between your users and their login pages. They’re not guessing passwords or cracking MFA codes; they’re waiting for authentication to succeed, to hijack the session.

Infoblox Threat Intel has uncovered a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting universities, enterprises, and multinational institutions, including European Union and United Nations agencies.

The interesting angle of this attack is procurement-themed emails sent from previously compromised organisational accounts, which make the messages appear credible. After a recipient clicks, this adversary-in-the-middle infrastructure intercepts credentials and authenticated session tokens in real time—even multi-factor authentication ones. This allows the attackers to bypass many of the controls organisations rely on to secure their identities.

For the recipient, the attack can look like an ordinary part of the workday: a bid invitation, a shared project file, or a request for information. False deadlines and confidentiality language create urgency, while familiar-looking screens make it seem as though victims are accessing a document or signing in as usual. Behind the scenes, the attacker is using that trusted process to gain access to the organisation’s account and network.

The actor appears to rotate among multiple phishing-as-a-service kits, including EvilProxy, FlowerStorm, and Kali365, while using compromised, often dormant, websites to host near-identical fake download pages. Those sites may look more trustworthy than newly created malicious domains, but their patterns, subdomain conventions, and reused infrastructure can still expose the campaign to defenders.

“These actors are using trust in organisational processes, like purchases, to convince people to hand over their credentials,” said Dr Renée Burton, Vice President of Infoblox Threat Intel. “It’s not a phishing scenario that you are usually warned about in security training.”

The findings reinforce the need for organisations to pair user awareness and identity controls with early visibility into the infrastructure behind phishing operations. DNS-based threat intelligence can help defenders identify campaign patterns upstream, before users reach fraudulent pages or attackers gain access to authenticated sessions.

To learn more, read the full research:https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/

CSA Editorial

Launched in Jan 2018, in partnership with Cyber Security Malaysia (an agency under MOSTI). CSA is a news and content platform focusing on key issues in cybersecurity in the region. CSA is targeted to serve the needs of cybersecurity professionals, IT professionals, Risk professionals and C-Levels who have an obligation to understand the impact of cyber threats.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *