1
Published signals
currently linked to this company
Company intelligence
infoblox.com
Infoblox is a cloud networking and security company specialising in DNS, DHCP and IP address management, collectively known as DDI.
1
currently linked to this company
1
recent published signals
1
recent published signals
1
confidence classifications
July 24, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Infoblox. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
Infoblox Threat Intel has identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign that began in May 2026 and was publicly reported on July 22, 2026. This campaign targets global organizations, including agencies associated with the European Union and the United Nations, as well as universities and commercial enterprises. The attackers utilize procurement-themed emails sent from previously compromised organizational accounts to bypass multi-factor authentication (MFA) and hijack authenticated sessions. These emails are designed to appear credible, mimicking routine business workflows such as bid invitations, shared project files, or requests for information, often incorporating false deadlines and confidentiality language to create urgency. When a recipient clicks an embedded link, the AiTM infrastructure intercepts credentials and session tokens in real-time, allowing attackers to gain access to the organization's account and network. The campaign leverages various Phishing-as-a-Service kits, including EvilProxy, FlowerStorm, and Kali365, and hosts fake download pages on compromised, often dormant, websites to enhance their apparent legitimacy. Infoblox emphasizes that this type of phishing scenario is not typically covered in standard security training, highlighting the need for organizations to combine user awareness with early visibility into phishing infrastructure through DNS-based threat intelligence.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Infoblox.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.