"The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions — Threadlinqs Intelligence
As of 2026-07-21, "The Procurement Trap": AiTM Phishing-as-a-Service Campaign (EvilProxy, FlowerStorm/Storm-1167, Kali365) Targeting Universities, EU/UN Agencies, and Multinational Institutions is a high-severity phishing threat attributed to Unknown (single actor operating EvilProxy, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-1593 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: Unknown (single actor operating EvilProxy · FINANCIAL
A single actor operating three separate adversary-in-the-middle (AiTM) phishing-as-a-service platforms — EvilProxy, FlowerStorm (Storm-1167/successor to Rockstar2FA), and Kali365 — is running
Infoblox threat intelligence identified in May 2026 a coordinated phishing infrastructure cluster that traces back to a single actor operating (or reselling access to) three distinct AiTM phishing-as-a-service (PhaaS) kits: EvilProxy (active since 2022, reverse-proxy AiTM), FlowerStorm (first seen June 2024, the successor to Rockstar2FA/Storm-1575 which partially collapsed on 2024-11-11), and Kali365 (first observed April 2026, pairs OAuth device-code phishing with AiTM cookie theft against Microsoft 365, subject of an FBI IC3 PSA on 2026-05-21 and shuttered by its own operators on 2026-05-21).
The attack chain begins with phishing emails sent from already-compromised organizational Outlook accounts, using procurement-themed lures (RFIs, bid invitations, project documentation) tailored to the target's business context. Victims click through to fake file-sharing/document portals hosted on a set of aged (6+ year old) compromised domains — barifurniture[.]net, satoriestate[.]com, sohantraders[.]com, testserveren[.]com, vresortsliving[.]com — that had been dormant for roughly a decade before being repurposed with injected index.php landing pages. These initial-stage pages solicit the victim's email address (used both for targeting confirmation and for pre-filling the subsequent phishing portal), then redirect to a second tier of purpose-registered RDGA (Randomly/Repetitively-Generated Domain Algorithm) domains built from corporate buzzword combinations under .de (FlowerStorm cluster) and .com/.net (EvilProxy cluster) TLDs. These second-tier domains front either a legitimate Cloudflare Turnstile CAPTCHA or an actor-controlled CAPTCHA clone, both used as a bot/sandbox-evasion gate before serving the final AiTM proxy page.
The final stage is a cloned authentication portal — most frequently a fake Microsoft/Microsoft 365 login, but with observed brand impersonation of OpenGov, ConstructConnect, the European Investment Bank, the United Nations, and NUS Consulting Group depending on the specific lure and target vertical. Because the phishing kit operates as a true reverse proxy, the victim's credentials and completed MFA challenge are relayed live to the legitimate identity provider while the AiTM framework transparently captures the resulting authenticated session cookie (and, for the Kali365 device-code flow, a long-lived OAuth refresh token) — giving the attacker full account access without needing to defeat MFA outright. Non-targeted visitors, scanners, and automated crawlers are cloaked to benign decoy content, a defense-evasion behavior consistent with all three PhaaS families.
Targeting spans universities and higher-education institutions, EU and UN agency personnel, US state/local government users of the OpenGov procurement platform, and enterprises in professional services, finance, legal, and manufacturing across North America, Europe, and other regions with EIB/UN engagement. This campaign sits within a broader 2025-2026 trend of AiTM PhaaS proliferation: Rockstar2FA's November 2024 partial collapse fed direct growth of FlowerStorm; a related but operationally distinct Evilginx-based actor ran a parallel campaign (April-November 2025) against at least 18 US universities using 67 attacker-owned domains and TinyURL-cloaked SSO lures, underscoring how commoditized AiTM tooling has made session-cookie theft the dominant MFA-bypass technique for both APT-adjacent and lower-skill financially motivated actors alike. No CVE applies — this is a social-engineering and identity-infrastructure abuse campaign, not a software vulnerability.
Weaknesses (CWE)
CWE-290, CWE-295, CWE-451
Target sectors: education, government administration, professional-services, finance, legal, manufacturing, international-organizations
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589.002, T1583.001, T1584.001, T1587.001, T1585.002, T1566.002, T1078.004, T1204.001, T1098.001, T1656