Back to news

Phishing Ops Exposed by Open Server; Cyber Startup Founders Face Fraud Scrutiny

Two stories converge on a single theme: threat actors undone by their own sloppiness, and a zero-day broker whose principals carry serious criminal baggage.

Phishing Ops Exposed by Open Server; Cyber Startup Founders Face Fraud Scrutiny

What happened

A threat actor running Microsoft 365 credential-harvesting campaigns using the Evilginx adversary-in-the-middle framework left a Python development server publicly accessible with directory listing enabled — a single command in the server's shell history gave investigators at French firm Lexfo a complete view of the operator's tooling. That one misstep allowed researchers to pivot from the exposed infrastructure and uncover two additional active phishing operations tied to the same actor. Separately, Krebs on Security identified the principals behind a cybersecurity startup publicly offering millions of dollars for zero-day vulnerabilities as convicted felons with documented histories of running fictitious intelligence firms and an AI-powered lobbying platform, both operated under assumed identities.

Why it matters for your business

The Evilginx exposure illustrates that even sophisticated phishing infrastructure can be dismantled when operators make elementary operational-security mistakes — but it also confirms that polished, multi-campaign adversaries are actively targeting Microsoft 365 environments at scale, meaning standard password policies are insufficient without phishing-resistant MFA such as FIDO2 hardware keys. The zero-day broker story carries a separate warning for security and procurement teams: vetting the provenance of vulnerability research services and tooling vendors matters, since purchasing offensive intelligence from operators with undisclosed criminal records or fabricated credentials creates legal, reputational, and supply-chain risk. Organizations should require background transparency and legal entity verification before engaging any external security research or bug-bounty intermediary.

What to watch next

Lexfo's pivot across three related phishing operations suggests law-enforcement referrals may follow; security teams should monitor for Evilginx-specific indicators of compromise and review conditional-access policies for Microsoft 365 tenant authentication. On the vendor-fraud front, regulators and state attorneys general have begun scrutinizing the nascent zero-day brokerage market, and the startup in question may face licensing or securities questions given its fundraising activity. Both cases signal a broader pattern of threat actors and fraudulent vendors relying on the assumption that buyers and defenders will not look closely at the infrastructure or the people behind it.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp