Techitup Middle East
Cybersecurity

Fake Procurement Email Phishing Targets Global Organizations

⏱️ 2 min read

Infoblox Threat Intel has uncovered a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting universities, enterprises and multinational institutions, including European Union and United Nations agencies. Infoblox says, right now, someone may be sitting invisibly between your users and their login pages. They’re not guessing passwords or cracking MFA codes; they’re waiting for authentication to succeed, to hijack the session.

According to Infoblox, the interesting angle of this attack is procurement-themed emails sent from previously compromised organizational accounts which make the messages appear credible. After a recipient clicks, this adversary-in-the-middle infrastructure intercepts credentials and authenticated session tokens in real time – even multi-factor authentication ones. This allows the attackers to bypass many of the controls organizations rely on to secure their identities.

How Phishing Campaigns Operate on a Normal Workday

For the recipient, the attack can look like an ordinary part of the workday: a bid invitation, a shared project file or a request for information. False deadlines and confidentiality language create urgency, while familiar-looking screens make it seem as though victims are accessing a document or signing in as usual. Behind the scenes, the attacker is using that trusted process to gain access to the organization’s account and network.

The actor appears to rotate among multiple phishing-as-a-service kits, including EvilProxy, FlowerStorm and Kali365, while using compromised, often dormant websites to host near-identical fake download pages. Those sites may look more trustworthy than newly created malicious domains, but their patterns, subdomain conventions and reused infrastructure can still expose the campaign to defenders, adds Infoblox.

“These actors are using trust in organizational processes, like purchases, to convince people to hand over their credentials,” said Dr. Renée Burton, Vice President of Infoblox Threat Intel. “It’s not a phishing scenario that you are usually warned about in security training.”


Related posts