CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account Takeover (Storm-1167 Overlap) — Threadlinqs Intelligence
As of 2026-06-23, CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account Takeover (Storm-1167 Overlap) is a high-severity phishing threat attributed to CodeStorm operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0913 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: CodeStorm operators · FINANCIAL
CodeStorm is an adversary-in-the-middle (AiTM) phishing-as-a-service kit that abuses compromised Microsoft 365 mailboxes to send SPF/DKIM/DMARC-passing voicemail lures, funnels victims through
CodeStorm is a previously undocumented adversary-in-the-middle (AiTM) phishing kit and operation that hijacks Microsoft 365 / Microsoft Entra ID accounts at scale. Initial access is achieved by abusing already-compromised M365 mailboxes — often those of known business partners with prior legitimate correspondence — to dispatch voicemail-notification lures that pass SPF, DKIM, and DMARC because they originate from authenticated sending infrastructure. The lures present a well-formatted Microsoft-branded message with a call duration, a reference ID, and an 'OPEN VOICEMAIL PORTAL' button. Secure email gateways are evaded through 'conversation stuffing' — a hidden whitespace block appending an unrelated dummy email thread — which also produces the tell-tale signature of From, To, and Return-Path headers all being identical.
The operation separates a rapidly rotating frontend (400+ apex domains, predominantly under the .de TLD, supporting roughly 12,000 subdomains) from a stable, tenant-aware backend controller exposed primarily at the path /google.php (alternate /next.php). Landing pages are gated by Cloudflare Turnstile, where the operator-supplied sitekey doubles as a per-operator identifier across distinct subdomains. Heavy client-side anti-analysis controls block developer tools and automation: checks for navigator.webdriver, window.callPhantom/_phantom, user-agent matching for 'Burp', suppression of F12/Ctrl+U/Ctrl+Shift+I and related shortcuts, right-click suppression, and a performance.now()-based debugger watchdog that redirects to legitimate Outlook on detection. A second-stage obfuscated JavaScript payload (bootstrap.min.js / bootstrappp.min.js) is delivered from Tencent Cloud Object Storage in the ap-seoul region (multiple recurring APPIDs) and begins with a base64-encoded operator harvester URL.
The backend's defining feature is a tenant-aware home-realm discovery matrix. A do=check action performs live home-realm discovery against Microsoft's real identity infrastructure, dynamically adapting the phishing flow based on whether the victim domain is a managed M365 tenant, a nonexistent user, a federated tenant, or a GoDaddy-managed account. A do=login action replays the submitted credentials against login.microsoftonline.com in real time — producing, within seconds, an OfficeHome Entra sign-in failure with error code 50126 (invalid username or password) in the victim tenant's logs, frequently from unexpected US geographies. A do=verify action triggers and intercepts MFA, with dedicated handlers for PhoneAppOTP (Authenticator OTP), PhoneAppNotification (push with number matching), and OneTimeCode (SMS/voice/email OTP), enabling theft and replay of the resulting session cookie. Post-compromise, the kit immediately creates an Outlook inbox rule (frequently named 'LinkedIn') that moves messages to 'RSS Feeds' and marks them read, then conducts SharePoint keyword reconnaissance and propagates onward phishing internally and to harvested contacts.
Hexastrike assesses with moderate confidence that CodeStorm overlaps with activity Microsoft tracks as Storm-1167, citing Tencent Cloud hosting reuse and Indonesian-language source-code artifacts (e.g., the helper parameter 'panjang', the error string 'Gagal memuat', the directory token 'ASLI') consistent with prior 2023 Microsoft reporting. The campaign has impacted 100+ confirmed tenants across roughly 600 targeted organizations, concentrated in North America and Western Europe across manufacturing, construction/real estate, healthcare/pharma, financial services, technology, government, and other sectors.
Weaknesses (CWE)
CWE-1021, CWE-290, CWE-294
Target sectors: manufacturing, construction, real estate, healthcare, pharmaceutical, financial services, technology, telecom, government, retail, energy, legal
Target regions: North America, Western Europe, Asia-Pacific, Africa, South America, Australia
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1586, T1566, T1566, T1566, T1078, T1098, T1564, T1027