Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01)

Misconfigured Python HTTP Server Exposes AiTM Phishing (TL-2026-1256), also tracked as Codemado AiTM Exposure, is a medium-severity phishing campaign, first published 2026-07-13. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID authentication, maps to 29 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 37 indicators of compromise.

Key facts for TL-2026-1256

Threat ID
TL-2026-1256
Also known as
Codemado AiTM Exposure, Lexfo Opendir Phishing Operator Disclosure
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-07-13
Last reviewed
2026-07-13
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, banking, cryptocurrency, professionalservices, technology, generalcorporate
Target regions
Global, North America, australia, canada
Detection rules
9
Indicators of compromise
37

Malware and tooling in Misconfigured Python HTTP Server Exposes AiTM Phishing

Malware and tooling: AsyncRAT, MaDoO Blaster v4.7.3, GetScreen, ITarian Endpoint Manager, ScreenConnect, SimpleHelp, SuperOps RMM, XEOX RMM, evilginx2 - S9003

Lexfo CTI researchers discovered an internet-exposed, misconfigured Python HTTP server (directory listing enabled) hosted in Budapest that revealed the complete operational toolkit of three distinct adversary-in-the-middle (AiTM) phishing operators — codemado, mail-argenta, and saroula01 — including customized Evilginx2 reverse-proxy forks, the custom bulk mailer 'MaDoO Blaster v4.7.3', a seven-tool RMM arsenal, credential-harvesting infrastructure, and operator credentials/Telegram/GitHub identities.

How Misconfigured Python HTTP Server Exposes AiTM Phishing works

On 2026-07-13, Lexfo's CTI team published findings from an internet-exposed Python HTTP server that had directory listing enabled, fully revealing the operational toolkit of a Microsoft 365-focused adversary-in-the-middle (AiTM) phishing ecosystem. The server, running at 185.163.204.7 (AS56322, ServerAstra, Budapest) and provisioned on 2026-03-13, hosted three customized Evilginx2 forks running simultaneously: 'saroula01/black-queen' (primary), 'mail-argenta/red-queen' (secondary), and additional clones used for A/B testing of phishing lures. The exposure ties together three overlapping but operationally distinct AiTM campaigns.

The primary operator, using the handle 'codemado' (aka MaDoO), is assessed as an Egyptian threat actor active since 2018, identified via GitHub repositories, Telegram sessions (@mad0o0o0o0o), and hardcoded credentials tied to the email codemadooo@gmail.com. Codemado's phishing infrastructure is centered on the domain picis[.]net with 30+ subdomains, including owa.picis[.]net (Outlook Web Access proxy), sso.picis[.]net (targeting National Australia Bank SSO), verify.picis[.]net (a custom Node.js anti-bot fingerprinting gateway using FingerprintJS2), and vinicious.picis[.]net (a ScreenConnect RMM console). Six social-engineering lure paths impersonate Microsoft Office, OneDrive, Microsoft Authenticator MFA prompts, Adobe PDF, DocuSign, and SharePoint. The toolkit harvests Primary Refresh Tokens (PRT) and ESTSAUTH session cookies with a 31,536,000-second (12-month) TTL that survives password resets, enabling long-term persistent M365 account access.

Codemado's custom bulk-mailer, MaDoO Blaster v4.7.3, supports multi-account SMTP rotation with per-account sending limits, a 'B2B mode' that abuses Microsoft Entra Client IDs to inject mail directly via the Microsoft Graph API, HTML template personalization (victim domain, company name, randomized strings), dynamic payload generation across PDF/DOCX/PPTX/ZIP/EML formats, a 'letter-to-image' conversion feature for spam-filter evasion, AI-generated voicemail (.wav) lures, QR-code-based per-recipient tracking, sender/From-address rotation, and an optional saveToSentItems flag to hide outbound phishing mail from the compromised mailbox. Codemado also deployed a seven-tool remote monitoring and management (RMM) arsenal for post-compromise access: a trojanized ScreenConnect installer distributed via the Telegram channel @hackers_assemble, SimpleHelp, SuperOps RMM (installed silently via /qn LicenseAccepted=YES), GetScreen.me (delivered by a VBScript stager), XEOX RMM (a VBScript dropper hosted on GitHub at codemado/api), ITarian Endpoint Manager v10.3.51334.25120, and a secondary AsyncRAT botnet (MaDOOOOOOOO_Work) with C2 at 83.136.211[.]85:7077 (a prior botnet C2 was observed at 188.227.196[.]240:7077). Payload delivery used multiple obfuscation layers: a 4.5MB obfuscated PowerShell script (dddd.ps1), a JScript dropper (Statement.js) using ActiveXObject, a three-layer VBScript-to-Base64-to-AES-encrypted delivery chain, trojanized MSI installers (AdobeClientSetupV16.msi, NEWPANEL.msi), and PowerShell disguised with a .jpg extension (dddd.jpg). Dedicated credential-stealer binaries pass.exe and getpass.exe were also recovered. Codemado credited the 'CyberNeurova' uncensored AI platform inline in code comments as an aid in malware development. A credential validation pipeline was also exposed: a Telethon script monitoring 100+ Telegram channels for combolists, a 100-thread SMTP credential checker (587_checker.py) validating against port 587, with confirmed-working accounts logged to Valid.log, and a QR-code redirect tracker (redir/app.js) that reports victim IP, country, and device type prior to serving the phishing page. Prior codemado activity was observed in January 2026 against queeenspropertyservices[.]ca.

The second operator, 'mail-argenta', is assessed as Nigerian and maintains 23 public GitHub repositories including multi-platform phishlets. Their Evilginx2 fork, 'red-queen', includes a Subresource Integrity (SRI) bypass that renames the crossorigin/integrity HTML attributes to rickorigin/tegridy to defeat browser SRI checks, a custom URL-rewriting engine in http_proxy.go, pre-filled victim-email injection to reduce user friction, and a pre-compiled evilginx2.exe binary. Mail-argenta's campaigns target Microsoft 365, the Kraken cryptocurrency exchange (via a Puppeteer-based MitM panel dubbed 'kraken-live-panel'), LinkedIn, eHarmony, GitHub, and Bybit. Operator attribution was made via credentials recovered from infostealer logs that matched the GitHub commit email and repository .env files; a reused MySQL password (Passionate1947.) was found hardcoded across the operator's personal accounts. Captured M365 sessions (ESTSAUTHPERSISTENT cookie) were valid through 2027-06-30.

The third operator, 'saroula01', remains unattributed but operates from Canadian-hosted Azure infrastructure at 20.118.27.127, using the domain romnor[.]ca. Rather than classic AiTM credential relay, saroula01's campaign abuses the OAuth Device Code Flow — a technique that bypasses MFA entirely by tricking victims into authorizing a device code on a legitimate Microsoft login page while the attacker polls for the resulting token. Six lure subdomains impersonate M365, OneDrive, Microsoft Authenticator, Adobe, DocuSign, and SharePoint (briefing/share/account/download/sign/team.romnor[.]ca/go). The campaign abused Microsoft's own first-party Office OAuth client ID (d3590ed6-52b3-4102-aeff-aad2292ab01c) to make device-code prompts appear legitimate, has been active since 2025-06-18, and had accumulated 218 confirmed victims across 12 countries at time of discovery (94% corporate). 97 harvested tokens had autoRefresh enabled and had been refreshed up to 25 times, providing durable persistent M365 access without any credential re-entry.

Lexfo also identified an ecosystem link: MaDoO Blaster is promoted by 'RockyBelling', operator of 'The Quarry' malware/phishing-as-a-service (MaaS/PhaaS) offering, inside the 'Rocky War Room' Telegram channel — indicating codemado functions as a third-party tool vendor to The Quarry's affiliate base rather than as a direct affiliate. A Cloudflare Tunnel (ID 1655dd1a-1c05-4818-8491-332f29713dca) was also identified as part of the exposed infrastructure, likely used to mask origin hosting for one or more of the phishing panels.

Collectively, the exposure demonstrates the fragility of operational security among AiTM phishing-as-a-service operators, the increasing sophistication of session-cookie and refresh-token theft techniques designed to defeat MFA, the growing convergence of AiTM phishing kits with commercial RMM tooling for post-compromise access, and abuse of legitimate cloud identity flows (OAuth Device Code Flow, Microsoft Graph API mail injection) to blend malicious activity into normal enterprise traffic.

MITRE ATT&CK techniques used in TL-2026-1256

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1219 Remote Access Tools

Persistence

T1078 Valid Accounts

Discovery

T1082 System Information Discovery

Credential Access

T1110 Brute Force; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle; T1621 Multi-Factor Authentication Request Generation

Collection

T1114 Email Collection; T1119 Automated Collection

Initial Access

T1199 Trusted Relationship; T1566 Phishing

Impact

T1531 Account Access Removal

lateral-movement

T1550 Use Alternate Authentication Material

defense-impairment

T1553 Subvert Trust Controls; T1685 Disable or Modify Tools

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in Misconfigured Python HTTP Server Exposes AiTM Phishing

  • Microsoft — Microsoft 365 / Entra ID authentication
    Vulnerable versions: all tenants using password/MFA authentication susceptible to AiTM relay or OAuth Device Code Flow
    Fixed in: phishing-resistant MFA (FIDO2/WebAuthn) with token binding
  • N/A — Python built-in HTTP server (SimpleHTTPServer/http.server) misconfiguration
    Vulnerable versions: any deployment run with directory listing enabled and exposed to the internet
    Fixed in: restrict binding to localhost/VPN, disable directory indexing, apply authentication

Remediation for Misconfigured Python HTTP Server Exposes AiTM Phishing

Immediate actions

  • Block network indicators: 185.163.204.7, 83.136.211.85, 188.227.196.240, 195.20.115.103, 20.118.27.127
  • Block phishing domains and subdomains: picis.net (and all subdomains), romnor.ca (and all subdomains), queeenspropertyservices.ca
  • Force revocation/re-issuance of Microsoft 365 refresh tokens and Primary Refresh Tokens (PRT) for any account suspected of interacting with picis.net or romnor.ca lures
  • Search email gateway logs for the six known lure URL paths (/update-verification, /admin-status-notice, /review-profile-alert, /user-credentials-required, /portal-security, /confirm-access) and romnor.ca/go paths
  • Hunt for unauthorized installs of ScreenConnect, SimpleHelp, SuperOps RMM, GetScreen.me, XEOX RMM, and ITarian Endpoint Manager not deployed by IT
  • Block file hashes for AdobeClientSetupV16.msi, dddd.ps1, and getpass.exe at EDR/AV

Workarounds

  • Enable Entra ID sign-in risk policies to flag logins from AiTM reverse-proxy infrastructure and impossible-travel patterns following token theft
  • Restrict RMM tool installation via application allow-listing to prevent silent trojanized RMM deployment

Longer-term hardening

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys) to eliminate AiTM session-relay and Device Code Flow bypass risk
  • Restrict or monitor OAuth Device Code Flow grants via Conditional Access policies; disable Device Code Flow for the Microsoft Office public client ID where not operationally required
  • Reduce Microsoft 365 refresh/session token lifetimes and enable continuous access evaluation (CAE) to shrink the AiTM persistence window
  • Deploy FIDO2-bound token binding or token protection policies in Entra ID to prevent stolen PRT/ESTSAUTH cookie replay
  • Monitor for anomalous Microsoft Graph API mail-send activity consistent with 'B2B mode' Entra Client ID abuse

Timeline of Misconfigured Python HTTP Server Exposes AiTM Phishing

  • Operator 'codemado' assessed as active in phishing/AiTM operations since 2018 per Lexfo attribution research
  • Saroula01's OAuth Device Code Flow phishing campaign against romnor[.]ca begins
  • Codemado observed running a prior phishing campaign against queeenspropertyservices[.]ca
  • Codemado's primary AiTM server infrastructure (185.163.204.7) provisioned in Budapest
  • Active phishing period begins for codemado's picis[.]net AiTM campaign
  • Codemado's picis[.]net AiTM campaign confirmed active through at least this date
  • Mail-argenta captured Microsoft 365 ESTSAUTHPERSISTENT session cookies valid through this date
  • Cyber Security News republishes summary coverage of the Lexfo disclosure
  • Lexfo CTI team publishes disclosure of the misconfigured Python HTTP server exposing all three AiTM operators' toolkits and infrastructure
  • Projected expiry date for mail-argenta's longest-lived captured M365 session token, illustrating long-term account-takeover persistence risk

Sources cited for Misconfigured Python HTTP Server Exposes AiTM Phishing

Threats related to Misconfigured Python HTTP Server Exposes AiTM Phishing

Detection coverage for TL-2026-1256

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1256 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1256

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats