Exposed Server Reveals Global Evilginx Phishing Campaigns Targeting Microsoft Accounts
AI-generated from multiple sources. Verify before acting on this reporting.
BUDAPEST — A misconfigured public server disclosed on July 13, 2026, has exposed three active phishing operations utilizing the Evilginx framework to harvest credentials from corporate users of Microsoft 365. The security breach revealed attacker toolkits and operational logs detailing campaigns orchestrated by individuals identified as codemado, mail-argenta, and saroula01.
The compromised server provided unfiltered access to infrastructure used in coordinated attacks spanning Hungary, Egypt, and Nigeria. Investigators found that the operators configured Evilginx proxies to mimic legitimate Microsoft login pages, allowing them to intercept authentication tokens without triggering standard multi-factor authentication alerts. The exposed logs indicate a sophisticated division of labor among the three actors, with mail-argenta operating out of Nigeria managing victim lists, while codemado and saroula01 maintained technical infrastructure in Budapest and Egypt respectively.
The discovery highlights a significant vulnerability in how threat actors manage their command-and-control environments. The server's configuration error allowed public access to sensitive data including phishing templates, session cookies, and real-time logs of compromised accounts. Analysts noted that the toolkits contained specific scripts designed to target enterprise email systems, prioritizing organizations with high-value Microsoft 365 subscriptions.
The operations appear to have been active for several weeks prior to exposure, though the exact duration remains unclear due to gaps in the recovered log files. The attackers utilized dynamic domain generation techniques to evade detection by security filters until the server misconfiguration occurred. Evidence suggests that mail-argenta coordinated the distribution of phishing links via social engineering campaigns targeting IT departments and finance teams.
Security experts warn that the exposure does not guarantee the immediate cessation of these operations, as threat actors often migrate infrastructure rapidly after a breach is detected. The identities of codemado, saroula01, and mail-argenta remain unverified beyond their online handles, complicating potential law enforcement actions across three different jurisdictions.
Questions persist regarding the full scope of data exfiltrated during these campaigns. While the server logs provided snapshots of successful credential thefts, it remains unknown how many corporate accounts were ultimately compromised or if stolen tokens are still being used to access sensitive internal networks. Authorities in Hungary and Egypt have not yet commented on whether investigations into local infrastructure providers have been initiated.
The incident serves as a stark reminder of the risks associated with cloud-based attack tools when deployed without adequate security controls by criminal operators. As digital forensics teams analyze the exposed data, organizations are urged to audit their Microsoft 365 access logs for signs of token theft and unauthorized session activity.