Infoblox Threat Intel has uncovered a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting universities, enterprises and multinational institutions, including European Union and United Nations agencies, by exploiting trust in everyday procurement workflows.
The operation, detailed by Infoblox on 23 July 2026, uses procurement-themed emails sent from previously compromised organisational accounts to make messages appear credible. Once a recipient clicks through, the AiTM infrastructure intercepts credentials and authenticated session tokens in real time, including multi-factor authentication (MFA), allowing attackers to bypass many of the controls organisations rely on to secure identities.
Trusted business workflows as the attack surface
For the recipient, the attack can look like an ordinary part of the workday: a bid invitation, a shared project file or a request for information. False deadlines and confidentiality language create urgency, while familiar-looking screens make it seem as though victims are accessing a document or signing in as usual. Behind the scenes, the attacker uses that trusted process to gain access to the organisation’s account and network.
The actor appears to rotate among multiple phishing-as-a-service kits, including EvilProxy, FlowerStorm and Kali365, while using compromised, often dormant websites to host near-identical fake download pages. Those sites may look more trustworthy than newly created malicious domains, but their patterns, subdomain conventions and reused infrastructure can still expose the campaign to defenders.
‘These actors are using trust in organizational processes, like purchases, to convince people to hand over their credentials,’ said Dr Renée Burton, Vice President of Infoblox Threat Intel. ‘It’s not a phishing scenario that you are usually warned about in security training.’
Visibility before users reach fraudulent pages
Infoblox said the findings reinforce the need for organisations to pair user awareness and identity controls with early visibility into the infrastructure behind phishing operations. DNS-based threat intelligence, it said, can help defenders identify campaign patterns upstream, before users reach fraudulent pages or attackers gain access to authenticated sessions.
Infoblox says it is trusted by more than 5,700 customers, including the majority of Fortune 100 companies, for DNS-based threat detection and response.



Share your thoughts