Evilginx Phishing Kits Are Hunting Microsoft 365 Logins

What happened
According to reporting from The Hacker News (via feeds.feedburner.com), French security firm Lexfo stumbled onto a live Microsoft 365 phishing operation because the attacker made a rookie mistake: they spun up a quick Python web server (python3 -m http.server 8080) on a public port with directory listing enabled, and left that command sitting in a readable .bash_history file. That single lapse exposed the operator's full toolkit.
From there, Lexfo pivoted through the infrastructure and identified two additional Evilginx phishing operations running against Microsoft 365 tenants. Evilginx is an "adversary-in-the-middle" (AiTM) framework — it proxies the real Microsoft login page in real time, harvests the victim's credentials, and, critically, steals the post-authentication session cookie so the attacker walks right past most forms of multi-factor authentication. Additional operator-specific details beyond what's in the report should be verified against Lexfo's own write-up before acting on them as fact.

Why this matters for Pittsburgh SMBs
If your business runs on Microsoft 365 — and for the accounting, legal, healthcare, professional services, and defense-contractor firms we work with across Pittsburgh, it almost certainly does — this is not a distant, enterprise-only threat. Evilginx and its cousins are the reason "we have MFA turned on" is no longer a sufficient answer when a cyber-insurance underwriter, a client security questionnaire, or a CMMC assessor asks how you protect user identities.
A few specific reasons this hits close to home for a 10–200-person firm in Western PA:
- You're the right size to be targeted. SMBs in professional services and manufacturing are actively prospected because attackers know the IT team is small, wire-transfer authority sits with a handful of people, and vendor/client email threads are lucrative to hijack.
- The compliance exposure is real. A stolen M365 session can expose PHI (HIPAA), client trust data (legal, CPA), CUI (CMMC/DFARS 7012), and customer financial records (FTC Safeguards, SOC 2). "MFA was on" will not save you in a breach investigation if the session cookie was replayed.
- Business email compromise is the payload. Once inside a mailbox, attackers typically set stealth inbox rules, watch for an invoice or closing statement, and then insert themselves into a live email thread. We see the aftermath of this pattern in Pittsburgh regularly — usually a redirected wire or a fraudulent ACH change.
- Defense contractors have a second problem. If a compromised M365 identity touches GCC/GCC High boundaries or CUI workflows, you may have a reportable incident under DFARS 252.204-7012's 72-hour clock.
The takeaway from the Lexfo find isn't "one bad guy got sloppy." It's that there are multiple, parallel operations running this playbook right now, and the same phishing kits get resold and reused.
What to do about it this week
You don't need a six-month project to blunt most of this. Start here:
- Turn on phishing-resistant MFA where you can. Move admins and high-risk users (finance, executives, HR, anyone with CUI or PHI access) off SMS and app-based push to FIDO2 security keys or Windows Hello for Business / passkeys. Evilginx-style AiTM cannot proxy a FIDO2 challenge.
- Enforce Conditional Access with device compliance. Require sign-ins from Intune-compliant or Entra-hybrid-joined devices for M365 access. A stolen cookie replayed from an attacker's VM in another country fails the device check.
- Shorten session lifetimes for privileged and sensitive roles. Reduce token lifetime and require reauthentication for admin portals, Exchange admin, and sensitive SharePoint sites. Sign-in frequency policies limit how long a stolen cookie is useful.
- Hunt for the tell-tale post-compromise behavior. Audit Exchange Online for new inbox rules that forward, delete, or move messages containing words like "invoice," "wire," "ACH," or "bank." This is the single highest-signal indicator of BEC in progress.
- Block or warn on newly registered look-alike domains. Your email security gateway and DNS filter should treat freshly registered domains and typosquats of your firm and your top clients/vendors with extra scrutiny. Many Evilginx landing pages live on domains less than a week old.
- Run a 20-minute tabletop with finance. "You receive an email from a partner changing their wire instructions. What do you do?" Confirm the out-of-band callback rule is written down, not just remembered, and that it applies even when the email comes from a legitimate, compromised account.
- Verify your logging retention. Purview/Entra sign-in and audit logs need to be retained long enough to actually investigate. Ninety days is a floor, not a target — CMMC, HIPAA, and cyber-insurance carriers increasingly expect more. Confirm what your tenant is actually keeping.
If any of the above prompts a "I'm not sure whether we do that," that's the finding — write it down and get it on next week's agenda.
How PGH Networks helps
Hardening Microsoft 365 against AiTM phishing is squarely in the middle of what we do for Pittsburgh SMBs every day: Conditional Access design, Intune compliance baselines, FIDO2 rollouts, Exchange rule monitoring, 24/7 identity-threat detection via MDR, and the compliance mapping that ties all of it back to HIPAA, SOC 2, CMMC, and the FTC Safeguards Rule. If you'd like us to run a no-obligation review of your M365 tenant against the checklist above, call 724.888.7007 or reach us through the contact form and we'll show you exactly where you stand — and what to fix first.
Related reading

Phishing Kits Bypassing Microsoft 365 MFA: What SMBs Should Do Now
Two new phishing kits are defeating Microsoft 365 MFA. Here's what Pittsburgh SMBs in legal, healthcare, CPA, and defense should do about it this week.

Azure Consulting in Pittsburgh, PA
Azure consulting in Pittsburgh, PA for small and mid-market firms: migration, security, FinOps, and Copilot enablement from a local team. Talk to an engineer.

Disaster Recovery Services in Washington, PA
Disaster recovery services in Washington, PA for small and mid-market businesses: tested RTOs, immutable backups, and local response from the Pittsburgh metro.