Skip to main content
Back to overview
High

Infoblox Uncovers Global AiTM Phishing Campaign Targeting EU and UN Agencies

Infoblox Threat Intel has identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign that began in May 2026 and was publicly reported on July 22, 2026.

Key points

  • Infoblox Threat Intel uncovered a global AiTM phishing campaign.
  • The campaign targets universities, commercial enterprises, and multinational institutions, including EU and UN agencies.
  • Attackers use procurement-themed emails from compromised accounts to bypass MFA and steal authenticated sessions.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Threat source not confirmed

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jul 22, 2026
Updated
Jul 24, 2026
Confidence
High
Evidence
6 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch phishing, executive impersonation and account-takeover exposure.

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

InfobloxData DisclosureInfoblox Uncovers Global AiTM PhishingCampaign Targeting EU and UNAgencies Infoblox Threat IntelAiTMEuropean Union and the UnitedNationsMFAThese

Quick context

Questions about this signal

What happened in this signal?

Infoblox Threat Intel has identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign that began in May 2026 and was publicly reported on July 22, 2026. This campaign targets global organizations, including agencies associated with the European Union and the United Nations, as well as universities and commercial enterprises. The attackers utilize procurement-themed emails sent from previously compromised organizational accounts to bypass multi-factor authentication (MFA) and hijack authenticated sessions. These emails are designed to appear credible, mimicking routine business workflows such as bid invitations, shared project files, or requests for information, often incorporating false deadlines and confidentiality language to create urgency. When a recipient clicks an embedded link, the AiTM infrastructure intercepts credentials and session tokens in real-time, allowing attackers to gain access to the organization's account and network. The campaign leverages various Phishing-as-a-Service kits, including EvilProxy, FlowerStorm, and Kali365, and hosts fake download pages on compromised, often dormant, websites to enhance their apparent legitimacy. Infoblox emphasizes that this type of phishing scenario is not typically covered in standard security training, highlighting the need for organizations to combine user awareness with early visibility into phishing infrastructure through DNS-based threat intelligence.

When was this signal reported?

Shadow Tier lists Jul 22, 2026 as the signal date.

Which organization is connected to this signal?

Infoblox is the organization connected to this public signal.

Explore Infoblox
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence