Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01) — Threadlinqs Intelligence
As of 2026-07-13, Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01) is a medium-severity phishing threat attributed to codemado, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 37 indicators of compromise.
Threat ID: TL-2026-1256 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
Attribution: codemado · FINANCIAL
Lexfo CTI researchers discovered an internet-exposed, misconfigured Python HTTP server (directory listing enabled) hosted in Budapest that revealed the complete operational toolkit of three distinct
On 2026-07-13, Lexfo's CTI team published findings from an internet-exposed Python HTTP server that had directory listing enabled, fully revealing the operational toolkit of a Microsoft 365-focused adversary-in-the-middle (AiTM) phishing ecosystem. The server, running at 185.163.204.7 (AS56322, ServerAstra, Budapest) and provisioned on 2026-03-13, hosted three customized Evilginx2 forks running simultaneously: 'saroula01/black-queen' (primary), 'mail-argenta/red-queen' (secondary), and additional clones used for A/B testing of phishing lures. The exposure ties together three overlapping but operationally distinct AiTM campaigns.
The primary operator, using the handle 'codemado' (aka MaDoO), is assessed as an Egyptian threat actor active since 2018, identified via GitHub repositories, Telegram sessions (@mad0o0o0o0o), and hardcoded credentials tied to the email codemadooo@gmail.com. Codemado's phishing infrastructure is centered on the domain picis[.]net with 30+ subdomains, including owa.picis[.]net (Outlook Web Access proxy), sso.picis[.]net (targeting National Australia Bank SSO), verify.picis[.]net (a custom Node.js anti-bot fingerprinting gateway using FingerprintJS2), and vinicious.picis[.]net (a ScreenConnect RMM console). Six social-engineering lure paths impersonate Microsoft Office, OneDrive, Microsoft Authenticator MFA prompts, Adobe PDF, DocuSign, and SharePoint. The toolkit harvests Primary Refresh Tokens (PRT) and ESTSAUTH session cookies with a 31,536,000-second (12-month) TTL that survives password resets, enabling long-term persistent M365 account access.
Codemado's custom bulk-mailer, MaDoO Blaster v4.7.3, supports multi-account SMTP rotation with per-account sending limits, a 'B2B mode' that abuses Microsoft Entra Client IDs to inject mail directly via the Microsoft Graph API, HTML template personalization (victim domain, company name, randomized strings), dynamic payload generation across PDF/DOCX/PPTX/ZIP/EML formats, a 'letter-to-image' conversion feature for spam-filter evasion, AI-generated voicemail (.wav) lures, QR-code-based per-recipient tracking, sender/From-address rotation, and an optional saveToSentItems flag to hide outbound phishing mail from the compromised mailbox. Codemado also deployed a seven-tool remote monitoring and management (RMM) arsenal for post-compromise access: a trojanized ScreenConnect installer distributed via the Telegram channel @hackers_assemble, SimpleHelp, SuperOps RMM (installed silently via /qn LicenseAccepted=YES), GetScreen.me (delivered by a VBScript stager), XEOX RMM (a VBScript dropper hosted on GitHub at codemado/api), ITarian Endpoint Manager v10.3.51334.25120, and a secondary AsyncRAT botnet (MaDOOOOOOOO_Work) with C2 at 83.136.211[.]85:7077 (a prior botnet C2 was observed at 188.227.196[.]240:7077). Payload delivery used multiple obfuscation layers: a 4.5MB obfuscated PowerShell script (dddd.ps1), a JScript dropper (Statement.js) using ActiveXObject, a three-layer VBScript-to-Base64-to-AES-encrypted delivery chain, trojanized MSI installers (AdobeClientSetupV16.msi, NEWPANEL.msi), and PowerShell disguised with a .jpg extension (dddd.jpg). Dedicated credential-stealer binaries pass.exe and getpass.exe were also recovered. Codemado credited the 'CyberNeurova' uncensored AI platform inline in code comments as an aid in malware development. A credential validation pipeline was also exposed: a Telethon script monitoring 100+ Telegram channels for combolists, a 100-thread SMTP credential checker (587_checker.py) validating against port 587, with confirmed-working accounts logged to Valid.log, and a QR-code redirect tracker (redir/app.js) that reports victim IP, country, and device type prior to serving the phishing page. Prior codemado activity was observed in January 2026 against queeenspropertyservices[.]ca.
The second operator, 'mail-argenta', is assessed as Nigerian and maintains 23 public GitHub repositories including multi-platform phishlets. Their Evilginx2
Target sectors: finance, banking, cryptocurrency, professionalservices, technology, generalcorporate
Target regions: Global, North America, australia, canada
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 37 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1583, T1587, T1588, T1586, T1566, T1199, T1059, T1059, T1204, T1078