"The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions
"The Procurement Trap" (TL-2026-1593), also tracked as The Procurement Trap, is a high-severity phishing campaign, first published 2026-07-21. It is attributed to FlowerStorm with low confidence, affects Microsoft Microsoft 365 / Entra ID authentication, maps to 24 MITRE ATT&CK techniques (T1036, T1056.003, T1078.004), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-1593
- Threat ID
- TL-2026-1593
- Also known as
- The Procurement Trap
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-21
- Last reviewed
- 2026-07-21
- Attribution
- FlowerStorm
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- education, government administration, professional-services, finance, legal, manufacturing, international-organizations
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in "The Procurement Trap"
Malware and tooling: EvilProxy, Evilginx, FlowerStorm, Kali365, Rockstar2FA
A single actor operating three separate adversary-in-the-middle (AiTM) phishing-as-a-service platforms — EvilProxy, FlowerStorm (Storm-1167/successor to Rockstar2FA), and Kali365 — is running procurement-themed phishing campaigns against universities, EU/UN agencies, and multinational enterprises across professional services, finance, legal, and manufacturing. The chain abuses compromised organizational email accounts to deliver RFI/bid lures, routes victims through aged compromised domains and RDGA-generated buzzword-domains gated by Cloudflare Turnstile CAPTCHA, and presents cloned Microsoft/OpenGov/ConstructConnect/European Investment Bank authentication portals to intercept credentials, MFA tokens, and session cookies in real time, defeating password- and MFA-based controls without ever cracking a password.
How "The Procurement Trap" works
Infoblox threat intelligence identified in May 2026 a coordinated phishing infrastructure cluster that traces back to a single actor operating (or reselling access to) three distinct AiTM phishing-as-a-service (PhaaS) kits: EvilProxy (active since 2022, reverse-proxy AiTM), FlowerStorm (first seen June 2024, the successor to Rockstar2FA/Storm-1575 which partially collapsed on 2024-11-11), and Kali365 (first observed April 2026, pairs OAuth device-code phishing with AiTM cookie theft against Microsoft 365, subject of an FBI IC3 PSA on 2026-05-21 and shuttered by its own operators on 2026-05-21).
The attack chain begins with phishing emails sent from already-compromised organizational Outlook accounts, using procurement-themed lures (RFIs, bid invitations, project documentation) tailored to the target's business context. Victims click through to fake file-sharing/document portals hosted on a set of aged (6+ year old) compromised domains — barifurniture[.]net, satoriestate[.]com, sohantraders[.]com, testserveren[.]com, vresortsliving[.]com — that had been dormant for roughly a decade before being repurposed with injected index.php landing pages. These initial-stage pages solicit the victim's email address (used both for targeting confirmation and for pre-filling the subsequent phishing portal), then redirect to a second tier of purpose-registered RDGA (Randomly/Repetitively-Generated Domain Algorithm) domains built from corporate buzzword combinations under .de (FlowerStorm cluster) and .com/.net (EvilProxy cluster) TLDs. These second-tier domains front either a legitimate Cloudflare Turnstile CAPTCHA or an actor-controlled CAPTCHA clone, both used as a bot/sandbox-evasion gate before serving the final AiTM proxy page.
The final stage is a cloned authentication portal — most frequently a fake Microsoft/Microsoft 365 login, but with observed brand impersonation of OpenGov, ConstructConnect, the European Investment Bank, the United Nations, and NUS Consulting Group depending on the specific lure and target vertical. Because the phishing kit operates as a true reverse proxy, the victim's credentials and completed MFA challenge are relayed live to the legitimate identity provider while the AiTM framework transparently captures the resulting authenticated session cookie (and, for the Kali365 device-code flow, a long-lived OAuth refresh token) — giving the attacker full account access without needing to defeat MFA outright. Non-targeted visitors, scanners, and automated crawlers are cloaked to benign decoy content, a defense-evasion behavior consistent with all three PhaaS families.
Targeting spans universities and higher-education institutions, EU and UN agency personnel, US state/local government users of the OpenGov procurement platform, and enterprises in professional services, finance, legal, and manufacturing across North America, Europe, and other regions with EIB/UN engagement. This campaign sits within a broader 2025-2026 trend of AiTM PhaaS proliferation: Rockstar2FA's November 2024 partial collapse fed direct growth of FlowerStorm; a related but operationally distinct Evilginx-based actor ran a parallel campaign (April-November 2025) against at least 18 US universities using 67 attacker-owned domains and TinyURL-cloaked SSO lures, underscoring how commoditized AiTM tooling has made session-cookie theft the dominant MFA-bypass technique for both APT-adjacent and lower-skill financially motivated actors alike. No CVE applies — this is a social-engineering and identity-infrastructure abuse campaign, not a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1593
Defense Evasion
Credential Access
T1056.003 Web Portal Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1621 Multi-Factor Authentication Request Generation
Initial Access
T1078.004 Cloud Accounts; T1566.002 Spearphishing Link
Command and Control
T1090.002 External Proxy; T1102 Web Service
Persistence
T1098.001 Additional Cloud Credentials
Collection
Execution
Discovery
T1518.001 Security Software Discovery
Impact
Lateral Movement
T1550.001 Application Access Token
lateral-movement
defense-impairment
T1556.006 Multi-Factor Authentication
Resource Development
T1583.001 Domains; T1584.001 Domains; T1585.002 Email Accounts; T1587.001 Malware
Reconnaissance
stealth
Affected products and versions in "The Procurement Trap"
- Microsoft — Microsoft 365 / Entra ID authentication
Vulnerable versions: all tenants without phishing-resistant MFA or CAE enforcement
Fixed in: N/A - social engineering / identity infrastructure abuse, not a software defect - OpenGov — OpenGov procurement platform (impersonated brand)
Vulnerable versions: N/A - brand impersonated by phishing portal, platform itself not exploited
Fixed in: N/A - ConstructConnect — ConstructConnect bid/procurement platform (impersonated brand)
Vulnerable versions: N/A - brand impersonated by phishing portal
Fixed in: N/A
Remediation for "The Procurement Trap"
Immediate actions
- Block/sinkhole the identified RDGA and compromised-host domain indicators at DNS/perimeter (barifurniture.net, satoriestate.com, sohantraders.com, testserveren.com, vresortsliving.com, consistenthostinghub.de, designenhancessatisfaction.de, evergreenhostingoptions.de, innovativegrowthstrategy.de, reliablecontinuitysolutions.de, sustainablegrowthlaunch.de, solidhostingservices.de, usersatisfactionlab.de, assessmentevaluationreport.com, corporatetermscompliance.com, employeehandbookcompliance.com, esignidentification.com, q1evaluationperformance.net, duemineral.uk)
- Force session/refresh-token revocation and re-authentication for any account that reached the identified proxy domains, especially Microsoft 365/Entra ID accounts
- Search email gateway/EDR logs for procurement-themed lures (RFI, bid invitation, contract, tender) originating from external partner or vendor mailboxes
- Restrict or monitor OAuth device-code authentication flows in Entra ID/Microsoft 365 tenants (Conditional Access policy to block device code flow where not required)
Workarounds
- Disable or tightly scope OAuth device-code grant flow tenant-wide where business need does not require it
- Enable Cloudflare Turnstile/CAPTCHA-aware web filtering to flag actor-controlled CAPTCHA clones
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) that cannot be relayed by AiTM reverse proxies
- Implement DNS-layer threat intelligence to flag RDGA/newly-repurposed aged-domain patterns before users click through
- Enforce Conditional Access token-binding / continuous access evaluation (CAE) in Microsoft Entra ID to shorten stolen-session usability window
- User awareness training on procurement/RFI-themed lures targeting supply-chain and vendor-facing staff
Weaknesses (CWE) in "The Procurement Trap"
CWE-290, CWE-295, CWE-451
Timeline of "The Procurement Trap"
- EvilProxy AiTM phishing-as-a-service kit publicly documented emerging on the dark web with reverse-proxy MFA-bypass capability.
- FlowerStorm phishing-as-a-service platform first observed online.
- Rockstar2FA (Storm-1575) AiTM PhaaS suffers a partial infrastructure collapse, driving customer migration toward FlowerStorm.
- FlowerStorm PhaaS usage surges as it fills the market gap left by Rockstar2FA's collapse; tracked by Microsoft-adjacent researchers as Storm-1167-associated infrastructure.
- A related but operationally distinct Evilginx-based AiTM actor begins targeting US universities, starting with the University of San Diego (67 attacker domains ultimately identified).
- Infoblox publishes findings on the Evilginx-based US university SSO phishing campaign (18+ institutions), a precursor/related body of DNS-based detection research to the procurement-trap findings.
- Branded Kali365 phishing activity becomes visible in the wild, roughly six weeks before its officially cited 'first observed' date.
- Kali365 phishing-as-a-service kit formally first observed, combining OAuth device-code phishing with AiTM session-cookie theft against Microsoft 365, distributed via Telegram.
- Infoblox identifies 'The Procurement Trap' campaign cluster tying EvilProxy, FlowerStorm, and Kali365 infrastructure to a single actor targeting universities, EU/UN agencies, and multinational institutions via procurement-themed lures.
- Kali365 operators announce they are officially closing the kit's website and discontinuing operations, effective immediately, following the FBI advisory.
- FBI Internet Crime Complaint Center (IC3) issues PSA 2026-05-21 warning of Kali365 hijacking Microsoft 365 access tokens via device-code phishing.
- The Register reports on the FBI Kali365 warning amid a broader surge in device-code phishing incidents.
- SpyCloud and ANY.RUN publish deep-dive technical analyses of the Kali365 kit's templates, token-browser tooling, and Telegram distribution model.
Sources cited for "The Procurement Trap"
- The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions
- New FlowerStorm Microsoft phishing service fills void left by Rockstar2FA
- Rockstar2FA Collapse Fuels Expansion of FlowerStorm Phishing-as-a-Service
- From Rockstar2FA to FlowerStorm: Investigating a Blooming Phishing-as-a-Service Platform
- Resecurity | EvilProxy Phishing-as-a-Service with MFA Bypass Emerged in Dark Web
- State-of-the-art phishing: MFA bypass
- Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit - From Telegram Hype to FBI Takedown Theater
- Inside Kali365, a Device Code Phishing Ecosystem
- FBI warns of Kali365 as device code phishing soars
- Internet Crime Complaint Center (IC3) | Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
- Phishing attack targets 18 US universities, bypassing MFA
- DNS Uncovers Infrastructure Used in SSO Attacks
- Entra ID OAuth Device Code Phishing via AiTM (Tycoon)
- Tricked by trust: How OAuth and device code flows get abused
- Adversary-in-the-Middle Phishing: How AiTM Bypasses MFA
Threats related to "The Procurement Trap"
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat Landscape
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
- Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)
- Browser-in-the-Browser Phishing Campaign Impersonates 34+ Brands' Job Postings to Steal Google Account Credentials
- Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public Sector
- AiTM Phishing Becomes Top Initial Access Vector for Law Firms: Tycoon2FA, ClickFix/NetSupport RAT, Teams Vishing (STAC4749), and Lumma Stealer Converge on the Legal Sector
Detection coverage for TL-2026-1593
As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1593 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.