PGH Networks

Evilginx Phishing Kits Are Hunting Microsoft 365 Logins

July 18, 2026· PGH Networks Team· 4 min readCloud & Microsoft 365
Evilginx Phishing Kits Are Hunting Microsoft 365 Logins

What happened

According to reporting from The Hacker News (via feeds.feedburner.com), French security firm Lexfo stumbled onto a live Microsoft 365 phishing operation because the attacker made a rookie mistake: they spun up a quick Python web server (python3 -m http.server 8080) on a public port with directory listing enabled, and left that command sitting in a readable .bash_history file. That single lapse exposed the operator's full toolkit.

From there, Lexfo pivoted through the infrastructure and identified two additional Evilginx phishing operations running against Microsoft 365 tenants. Evilginx is an "adversary-in-the-middle" (AiTM) framework — it proxies the real Microsoft login page in real time, harvests the victim's credentials, and, critically, steals the post-authentication session cookie so the attacker walks right past most forms of multi-factor authentication. Additional operator-specific details beyond what's in the report should be verified against Lexfo's own write-up before acting on them as fact.

Detailed close-up of ethernet cables and network connections on a router, showcasing modern technology.

Why this matters for Pittsburgh SMBs

If your business runs on Microsoft 365 — and for the accounting, legal, healthcare, professional services, and defense-contractor firms we work with across Pittsburgh, it almost certainly does — this is not a distant, enterprise-only threat. Evilginx and its cousins are the reason "we have MFA turned on" is no longer a sufficient answer when a cyber-insurance underwriter, a client security questionnaire, or a CMMC assessor asks how you protect user identities.

A few specific reasons this hits close to home for a 10–200-person firm in Western PA:

  • You're the right size to be targeted. SMBs in professional services and manufacturing are actively prospected because attackers know the IT team is small, wire-transfer authority sits with a handful of people, and vendor/client email threads are lucrative to hijack.
  • The compliance exposure is real. A stolen M365 session can expose PHI (HIPAA), client trust data (legal, CPA), CUI (CMMC/DFARS 7012), and customer financial records (FTC Safeguards, SOC 2). "MFA was on" will not save you in a breach investigation if the session cookie was replayed.
  • Business email compromise is the payload. Once inside a mailbox, attackers typically set stealth inbox rules, watch for an invoice or closing statement, and then insert themselves into a live email thread. We see the aftermath of this pattern in Pittsburgh regularly — usually a redirected wire or a fraudulent ACH change.
  • Defense contractors have a second problem. If a compromised M365 identity touches GCC/GCC High boundaries or CUI workflows, you may have a reportable incident under DFARS 252.204-7012's 72-hour clock.

The takeaway from the Lexfo find isn't "one bad guy got sloppy." It's that there are multiple, parallel operations running this playbook right now, and the same phishing kits get resold and reused.

What to do about it this week

You don't need a six-month project to blunt most of this. Start here:

  1. Turn on phishing-resistant MFA where you can. Move admins and high-risk users (finance, executives, HR, anyone with CUI or PHI access) off SMS and app-based push to FIDO2 security keys or Windows Hello for Business / passkeys. Evilginx-style AiTM cannot proxy a FIDO2 challenge.
  2. Enforce Conditional Access with device compliance. Require sign-ins from Intune-compliant or Entra-hybrid-joined devices for M365 access. A stolen cookie replayed from an attacker's VM in another country fails the device check.
  3. Shorten session lifetimes for privileged and sensitive roles. Reduce token lifetime and require reauthentication for admin portals, Exchange admin, and sensitive SharePoint sites. Sign-in frequency policies limit how long a stolen cookie is useful.
  4. Hunt for the tell-tale post-compromise behavior. Audit Exchange Online for new inbox rules that forward, delete, or move messages containing words like "invoice," "wire," "ACH," or "bank." This is the single highest-signal indicator of BEC in progress.
  5. Block or warn on newly registered look-alike domains. Your email security gateway and DNS filter should treat freshly registered domains and typosquats of your firm and your top clients/vendors with extra scrutiny. Many Evilginx landing pages live on domains less than a week old.
  6. Run a 20-minute tabletop with finance. "You receive an email from a partner changing their wire instructions. What do you do?" Confirm the out-of-band callback rule is written down, not just remembered, and that it applies even when the email comes from a legitimate, compromised account.
  7. Verify your logging retention. Purview/Entra sign-in and audit logs need to be retained long enough to actually investigate. Ninety days is a floor, not a target — CMMC, HIPAA, and cyber-insurance carriers increasingly expect more. Confirm what your tenant is actually keeping.

If any of the above prompts a "I'm not sure whether we do that," that's the finding — write it down and get it on next week's agenda.

How PGH Networks helps

Hardening Microsoft 365 against AiTM phishing is squarely in the middle of what we do for Pittsburgh SMBs every day: Conditional Access design, Intune compliance baselines, FIDO2 rollouts, Exchange rule monitoring, 24/7 identity-threat detection via MDR, and the compliance mapping that ties all of it back to HIPAA, SOC 2, CMMC, and the FTC Safeguards Rule. If you'd like us to run a no-obligation review of your M365 tenant against the checklist above, call 724.888.7007 or reach us through the contact form and we'll show you exactly where you stand — and what to fix first.

Share

Related reading

Azure Consulting in Pittsburgh, PA

Azure consulting in Pittsburgh, PA for small and mid-market firms: migration, security, FinOps, and Copilot enablement from a local team. Talk to an engineer.