"The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions

"The Procurement Trap" (TL-2026-1593), also tracked as The Procurement Trap, is a high-severity phishing campaign, first published 2026-07-21. It is attributed to FlowerStorm with low confidence, affects Microsoft Microsoft 365 / Entra ID authentication, maps to 24 MITRE ATT&CK techniques (T1036, T1056.003, T1078.004), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-1593

Threat ID
TL-2026-1593
Also known as
The Procurement Trap
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-21
Last reviewed
2026-07-21
Attribution
FlowerStorm
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
education, government administration, professional-services, finance, legal, manufacturing, international-organizations
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
31

Malware and tooling in "The Procurement Trap"

Malware and tooling: EvilProxy, Evilginx, FlowerStorm, Kali365, Rockstar2FA

A single actor operating three separate adversary-in-the-middle (AiTM) phishing-as-a-service platforms — EvilProxy, FlowerStorm (Storm-1167/successor to Rockstar2FA), and Kali365 — is running procurement-themed phishing campaigns against universities, EU/UN agencies, and multinational enterprises across professional services, finance, legal, and manufacturing. The chain abuses compromised organizational email accounts to deliver RFI/bid lures, routes victims through aged compromised domains and RDGA-generated buzzword-domains gated by Cloudflare Turnstile CAPTCHA, and presents cloned Microsoft/OpenGov/ConstructConnect/European Investment Bank authentication portals to intercept credentials, MFA tokens, and session cookies in real time, defeating password- and MFA-based controls without ever cracking a password.

How "The Procurement Trap" works

Infoblox threat intelligence identified in May 2026 a coordinated phishing infrastructure cluster that traces back to a single actor operating (or reselling access to) three distinct AiTM phishing-as-a-service (PhaaS) kits: EvilProxy (active since 2022, reverse-proxy AiTM), FlowerStorm (first seen June 2024, the successor to Rockstar2FA/Storm-1575 which partially collapsed on 2024-11-11), and Kali365 (first observed April 2026, pairs OAuth device-code phishing with AiTM cookie theft against Microsoft 365, subject of an FBI IC3 PSA on 2026-05-21 and shuttered by its own operators on 2026-05-21).

The attack chain begins with phishing emails sent from already-compromised organizational Outlook accounts, using procurement-themed lures (RFIs, bid invitations, project documentation) tailored to the target's business context. Victims click through to fake file-sharing/document portals hosted on a set of aged (6+ year old) compromised domains — barifurniture[.]net, satoriestate[.]com, sohantraders[.]com, testserveren[.]com, vresortsliving[.]com — that had been dormant for roughly a decade before being repurposed with injected index.php landing pages. These initial-stage pages solicit the victim's email address (used both for targeting confirmation and for pre-filling the subsequent phishing portal), then redirect to a second tier of purpose-registered RDGA (Randomly/Repetitively-Generated Domain Algorithm) domains built from corporate buzzword combinations under .de (FlowerStorm cluster) and .com/.net (EvilProxy cluster) TLDs. These second-tier domains front either a legitimate Cloudflare Turnstile CAPTCHA or an actor-controlled CAPTCHA clone, both used as a bot/sandbox-evasion gate before serving the final AiTM proxy page.

The final stage is a cloned authentication portal — most frequently a fake Microsoft/Microsoft 365 login, but with observed brand impersonation of OpenGov, ConstructConnect, the European Investment Bank, the United Nations, and NUS Consulting Group depending on the specific lure and target vertical. Because the phishing kit operates as a true reverse proxy, the victim's credentials and completed MFA challenge are relayed live to the legitimate identity provider while the AiTM framework transparently captures the resulting authenticated session cookie (and, for the Kali365 device-code flow, a long-lived OAuth refresh token) — giving the attacker full account access without needing to defeat MFA outright. Non-targeted visitors, scanners, and automated crawlers are cloaked to benign decoy content, a defense-evasion behavior consistent with all three PhaaS families.

Targeting spans universities and higher-education institutions, EU and UN agency personnel, US state/local government users of the OpenGov procurement platform, and enterprises in professional services, finance, legal, and manufacturing across North America, Europe, and other regions with EIB/UN engagement. This campaign sits within a broader 2025-2026 trend of AiTM PhaaS proliferation: Rockstar2FA's November 2024 partial collapse fed direct growth of FlowerStorm; a related but operationally distinct Evilginx-based actor ran a parallel campaign (April-November 2025) against at least 18 US universities using 67 attacker-owned domains and TinyURL-cloaked SSO lures, underscoring how commoditized AiTM tooling has made session-cookie theft the dominant MFA-bypass technique for both APT-adjacent and lower-skill financially motivated actors alike. No CVE applies — this is a social-engineering and identity-infrastructure abuse campaign, not a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1593

Defense Evasion

T1036 Masquerading

Credential Access

T1056.003 Web Portal Capture; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1621 Multi-Factor Authentication Request Generation

Initial Access

T1078.004 Cloud Accounts; T1566.002 Spearphishing Link

Command and Control

T1090.002 External Proxy; T1102 Web Service

Persistence

T1098.001 Additional Cloud Credentials

Collection

T1114 Email Collection

Execution

T1204.001 Malicious Link

Discovery

T1518.001 Security Software Discovery

Impact

T1531 Account Access Removal

Lateral Movement

T1550.001 Application Access Token

lateral-movement

T1550.004 Web Session Cookie

defense-impairment

T1556.006 Multi-Factor Authentication

Resource Development

T1583.001 Domains; T1584.001 Domains; T1585.002 Email Accounts; T1587.001 Malware

Reconnaissance

T1589.002 Email Addresses

stealth

T1684.001 Impersonation

Affected products and versions in "The Procurement Trap"

  • Microsoft — Microsoft 365 / Entra ID authentication
    Vulnerable versions: all tenants without phishing-resistant MFA or CAE enforcement
    Fixed in: N/A - social engineering / identity infrastructure abuse, not a software defect
  • OpenGov — OpenGov procurement platform (impersonated brand)
    Vulnerable versions: N/A - brand impersonated by phishing portal, platform itself not exploited
    Fixed in: N/A
  • ConstructConnect — ConstructConnect bid/procurement platform (impersonated brand)
    Vulnerable versions: N/A - brand impersonated by phishing portal
    Fixed in: N/A

Remediation for "The Procurement Trap"

Immediate actions

  • Block/sinkhole the identified RDGA and compromised-host domain indicators at DNS/perimeter (barifurniture.net, satoriestate.com, sohantraders.com, testserveren.com, vresortsliving.com, consistenthostinghub.de, designenhancessatisfaction.de, evergreenhostingoptions.de, innovativegrowthstrategy.de, reliablecontinuitysolutions.de, sustainablegrowthlaunch.de, solidhostingservices.de, usersatisfactionlab.de, assessmentevaluationreport.com, corporatetermscompliance.com, employeehandbookcompliance.com, esignidentification.com, q1evaluationperformance.net, duemineral.uk)
  • Force session/refresh-token revocation and re-authentication for any account that reached the identified proxy domains, especially Microsoft 365/Entra ID accounts
  • Search email gateway/EDR logs for procurement-themed lures (RFI, bid invitation, contract, tender) originating from external partner or vendor mailboxes
  • Restrict or monitor OAuth device-code authentication flows in Entra ID/Microsoft 365 tenants (Conditional Access policy to block device code flow where not required)

Workarounds

  • Disable or tightly scope OAuth device-code grant flow tenant-wide where business need does not require it
  • Enable Cloudflare Turnstile/CAPTCHA-aware web filtering to flag actor-controlled CAPTCHA clones

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware keys) that cannot be relayed by AiTM reverse proxies
  • Implement DNS-layer threat intelligence to flag RDGA/newly-repurposed aged-domain patterns before users click through
  • Enforce Conditional Access token-binding / continuous access evaluation (CAE) in Microsoft Entra ID to shorten stolen-session usability window
  • User awareness training on procurement/RFI-themed lures targeting supply-chain and vendor-facing staff

Weaknesses (CWE) in "The Procurement Trap"

CWE-290, CWE-295, CWE-451

Timeline of "The Procurement Trap"

  • EvilProxy AiTM phishing-as-a-service kit publicly documented emerging on the dark web with reverse-proxy MFA-bypass capability.
  • FlowerStorm phishing-as-a-service platform first observed online.
  • Rockstar2FA (Storm-1575) AiTM PhaaS suffers a partial infrastructure collapse, driving customer migration toward FlowerStorm.
  • FlowerStorm PhaaS usage surges as it fills the market gap left by Rockstar2FA's collapse; tracked by Microsoft-adjacent researchers as Storm-1167-associated infrastructure.
  • A related but operationally distinct Evilginx-based AiTM actor begins targeting US universities, starting with the University of San Diego (67 attacker domains ultimately identified).
  • Infoblox publishes findings on the Evilginx-based US university SSO phishing campaign (18+ institutions), a precursor/related body of DNS-based detection research to the procurement-trap findings.
  • Branded Kali365 phishing activity becomes visible in the wild, roughly six weeks before its officially cited 'first observed' date.
  • Kali365 phishing-as-a-service kit formally first observed, combining OAuth device-code phishing with AiTM session-cookie theft against Microsoft 365, distributed via Telegram.
  • Infoblox identifies 'The Procurement Trap' campaign cluster tying EvilProxy, FlowerStorm, and Kali365 infrastructure to a single actor targeting universities, EU/UN agencies, and multinational institutions via procurement-themed lures.
  • Kali365 operators announce they are officially closing the kit's website and discontinuing operations, effective immediately, following the FBI advisory.
  • FBI Internet Crime Complaint Center (IC3) issues PSA 2026-05-21 warning of Kali365 hijacking Microsoft 365 access tokens via device-code phishing.
  • The Register reports on the FBI Kali365 warning amid a broader surge in device-code phishing incidents.
  • SpyCloud and ANY.RUN publish deep-dive technical analyses of the Kali365 kit's templates, token-browser tooling, and Telegram distribution model.

Sources cited for "The Procurement Trap"

Threats related to "The Procurement Trap"

Detection coverage for TL-2026-1593

As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1593 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats